logo

You Thought It Was Over? Authentication Coercion Keeps Evolving

ID: f4a55b61-ae1b-5561-86a7-08da5c31572e

STIX ID: report--f4a55b61-ae1b-5561-86a7-08da5c31572e

Feed Name: Palo Alto Networks Unit 42

Threat Score
80/100

Date Published: 2025-11-11

Date Updated: 2026-04-28

Author: Bar Maor and Hila Cohen

...
...

This Unit 42 report explains authentication coercion attacks where adversaries abuse Windows RPC interfaces (including rarely used opnums) to force target systems to authenticate to attacker-controlled hosts, enabling theft of NTLM hashes and potential domain compromise; it includes a March 2025 case using the MS-EVEN ElfrOpenBELW function, discusses known tools (e.g., PetitPotam, PrintNightmare), and provides detection, monitoring and hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.