You Thought It Was Over? Authentication Coercion Keeps Evolving
ID: f4a55b61-ae1b-5561-86a7-08da5c31572e
STIX ID: report--f4a55b61-ae1b-5561-86a7-08da5c31572e
Feed Name: Palo Alto Networks Unit 42
Threat Score
This Unit 42 report explains authentication coercion attacks where adversaries abuse Windows RPC interfaces (including rarely used opnums) to force target systems to authenticate to attacker-controlled hosts, enabling theft of NTLM hashes and potential domain compromise; it includes a March 2025 case using the MS-EVEN ElfrOpenBELW function, discusses known tools (e.g., PetitPotam, PrintNightmare), and provides detection, monitoring and hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
