Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit SPN Gaps for Stealthy Kerberoasting

Hackers Exploit SPN Gaps for Stealthy Kerberoasting

Posted on August 28, 2026 By CWS

Cybercriminals are increasingly taking advantage of overlooked misconfigurations in Active Directory service principal names (SPNs) to execute more covert Kerberoasting attacks. This shift allows attackers to target regular user accounts as high-value credential sources.

Innovative Attack Technique

Researchers at Trellix have identified a method they call “Ghost SPN,” which enables attackers with certain directory privileges to temporarily assign an SPN to a standard account. This maneuver allows them to request a Kerberos service ticket and subsequently erase traces of the change, evading detection by security teams.

Kerberoasting, a credential access strategy recognized as MITRE ATT&CK T1558.003, involves attackers with a valid Kerberos ticket-granting ticket requesting ticket-granting service (TGS) tickets for accounts linked to SPNs. These tickets can be utilized to attempt offline password cracking without the need for repeated domain authentication.

Understanding SPN Vulnerabilities

Typically, SPNs are used to identify services such as Microsoft SQL Server or LDAP instances that depend on Kerberos authentication. Security audits often prioritize these service accounts, assuming they are tied to dedicated service identities. However, the Ghost SPN technique exploits this assumption by attaching an SPN to a regular user account through delegated permissions, bypassing established administrative protocols.

Once the SPN is assigned, the account can request Kerberos service tickets and attackers can enumerate SPNs across the domain to identify potential targets. These tickets may be encrypted using RC4-HMAC, a weaker encryption standard, making them more appealing for attackers due to the ease of offline cracking.

Mitigation Strategies

Detecting these attacks can be challenging as they generate minimal noise and can be brief in execution. Trellix suggests focusing on auditing Active Directory permissions and monitoring anomalous Kerberos service-ticket requests, particularly those employing RC4 encryption.

Organizations are advised to reduce the number of accounts capable of producing vulnerable service tickets by transitioning to managed service accounts with centrally managed credentials. When possible, AES encryption should be enforced to secure Kerberos tickets, and RC4 should be disabled to minimize susceptibility to these attacks.

Furthermore, reviewing permissions that allow users to modify account objects and setting alerts for unexpected SPN changes can help in early detection and prevention of such incidents.

In conclusion, while these SPN misconfigurations present significant risks, a proactive approach involving the use of updated security practices and vigilant monitoring can mitigate potential threats posed by these advanced attack techniques.

Cyber Security News Tags:Active Directory, Cybersecurity, Hacking, Kerberoasting, MITRE ATT&CK, password cracking, RC4 encryption, Security, SPN, Trellix

Post navigation

Previous Post: Critical cPanel Security Flaw Patched to Prevent Root Access

Related Posts

GitHub Authentication Glitch Impacts Automation Services GitHub Authentication Glitch Impacts Automation Services Cyber Security News
Apple Releases Critical iOS Update to Combat DarkSword Threat Apple Releases Critical iOS Update to Combat DarkSword Threat Cyber Security News
Lenovo Vantage Vulnerabilities Allow Attackers to Escalate Privileges as SYSTEM User Lenovo Vantage Vulnerabilities Allow Attackers to Escalate Privileges as SYSTEM User Cyber Security News
X-VPN’s August Update Lets Mobile Users Choose Servers in 26 Regions with Military-grade AES-256 Encryption X-VPN’s August Update Lets Mobile Users Choose Servers in 26 Regions with Military-grade AES-256 Encryption Cyber Security News
17-year-old Hacker Responsible for Vegas Casinos Hack has Been Released 17-year-old Hacker Responsible for Vegas Casinos Hack has Been Released Cyber Security News
VMware ESXi & vCenter Vulnerability Let Attackers Run Arbitrary Commands VMware ESXi & vCenter Vulnerability Let Attackers Run Arbitrary Commands Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit SPN Gaps for Stealthy Kerberoasting
  • Critical cPanel Security Flaw Patched to Prevent Root Access
  • Dark Caracal Hackers Leverage Ethereum for Malware Resilience
  • PaperCut Issues Urgent Fix for Zero-Day Exploit
  • PaperCut Zero-Day Vulnerability Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit SPN Gaps for Stealthy Kerberoasting
  • Critical cPanel Security Flaw Patched to Prevent Root Access
  • Dark Caracal Hackers Leverage Ethereum for Malware Resilience
  • PaperCut Issues Urgent Fix for Zero-Day Exploit
  • PaperCut Zero-Day Vulnerability Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark