Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit SPN Gaps for Stealthy Kerberoasting

Hackers Exploit SPN Gaps for Stealthy Kerberoasting

Posted on August 28, 2026 By CWS

Cybercriminals are increasingly taking advantage of overlooked misconfigurations in Active Directory service principal names (SPNs) to execute more covert Kerberoasting attacks. This shift allows attackers to target regular user accounts as high-value credential sources.

Innovative Attack Technique

Researchers at Trellix have identified a method they call “Ghost SPN,” which enables attackers with certain directory privileges to temporarily assign an SPN to a standard account. This maneuver allows them to request a Kerberos service ticket and subsequently erase traces of the change, evading detection by security teams.

Kerberoasting, a credential access strategy recognized as MITRE ATT&CK T1558.003, involves attackers with a valid Kerberos ticket-granting ticket requesting ticket-granting service (TGS) tickets for accounts linked to SPNs. These tickets can be utilized to attempt offline password cracking without the need for repeated domain authentication.

Understanding SPN Vulnerabilities

Typically, SPNs are used to identify services such as Microsoft SQL Server or LDAP instances that depend on Kerberos authentication. Security audits often prioritize these service accounts, assuming they are tied to dedicated service identities. However, the Ghost SPN technique exploits this assumption by attaching an SPN to a regular user account through delegated permissions, bypassing established administrative protocols.

Once the SPN is assigned, the account can request Kerberos service tickets and attackers can enumerate SPNs across the domain to identify potential targets. These tickets may be encrypted using RC4-HMAC, a weaker encryption standard, making them more appealing for attackers due to the ease of offline cracking.

Mitigation Strategies

Detecting these attacks can be challenging as they generate minimal noise and can be brief in execution. Trellix suggests focusing on auditing Active Directory permissions and monitoring anomalous Kerberos service-ticket requests, particularly those employing RC4 encryption.

Organizations are advised to reduce the number of accounts capable of producing vulnerable service tickets by transitioning to managed service accounts with centrally managed credentials. When possible, AES encryption should be enforced to secure Kerberos tickets, and RC4 should be disabled to minimize susceptibility to these attacks.

Furthermore, reviewing permissions that allow users to modify account objects and setting alerts for unexpected SPN changes can help in early detection and prevention of such incidents.

In conclusion, while these SPN misconfigurations present significant risks, a proactive approach involving the use of updated security practices and vigilant monitoring can mitigate potential threats posed by these advanced attack techniques.

Cyber Security News Tags:Active Directory, Cybersecurity, Hacking, Kerberoasting, MITRE ATT&CK, password cracking, RC4 encryption, Security, SPN, Trellix

Post navigation

Previous Post: Critical cPanel Security Flaw Patched to Prevent Root Access
Next Post: Critical ServiceNow Vulnerabilities Demand Urgent Attention

Related Posts

RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders Cyber Security News
Hackers Leverage Judicial Notifications to Deploy Info-Stealer Malware Hackers Leverage Judicial Notifications to Deploy Info-Stealer Malware Cyber Security News
Craneware Confirms Cyberattack, Data Compromised Craneware Confirms Cyberattack, Data Compromised Cyber Security News
Anthropic’s Claude Code Source Leak via npm Registry Anthropic’s Claude Code Source Leak via npm Registry Cyber Security News
Bimbo Bakeries Hit by Oracle EBS Data Breach Bimbo Bakeries Hit by Oracle EBS Data Breach Cyber Security News
Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark