Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials via msDS-KeyCredentialLink (CVE-2022-26923, Fog Ransomware, Fighting Ursa)
Unit 42 Deep Dive (TL-2026-0497), also tracked as Certifried, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-05-11. It is attributed to APT28 (Russia) with high confidence, affects Microsoft Active Directory Domain Services, references 1 CVE (CVE-2022-26923), maps to 18 MITRE ATT&CK techniques (T1003, T1021, T1059), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0497
- Threat ID
- TL-2026-0497
- Also known as
- Certifried, AD CS ESC1, Shadow Credentials Attack, Key Trust Abuse, Certified Pre-Owned
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-05-11
- Last reviewed
- 2026-05-11
- Attribution
- APT28
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, defense, energy, financial, healthcare, manufacturing, technology, managed_service_providers, education
- Target regions
- North America, Europe, United Kingdom, Ukraine, NATO Member States
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Unit 42 Deep Dive
Malware and tooling: Fog Ransomware, Certify.exe, Certipy, Cobalt Strike, PKINITtools, Rubeus - S1071, Whisker.exe, pyWhisker
Unit 42 (Palo Alto Networks) published a comprehensive technical deep-dive cataloguing Active Directory Certificate Services (AD CS) abuse techniques including ESC1 certificate template misconfigurations and Shadow Credential / Key Trust attacks via the msDS-KeyCredentialLink attribute (CVE-2022-26923). The research confirms active exploitation by Fog ransomware affiliates (DFIR Report telemetry) and Russian GRU-linked Fighting Ursa (APT28 / Forest Blizzard), enabled by mature open-source tooling (Certify, Certipy supporting ESC1–ESC16, Whisker, pyWhisker, PKINITtools). AD CS abuse converts a single low-privilege foothold into full domain compromise with minimal native detection coverage.
How Unit 42 Deep Dive works
Unit 42's May 2026 publication consolidates four years of AD CS attack research into a single operational reference for defenders, documenting how attackers exploit certificate-based authentication to achieve domain dominance. The article focuses on two primary attack classes — Certificate Template Misconfigurations (the SpecterOps ESC1–ESC16 taxonomy from Schroeder and Christensen's 2021 'Certified Pre-Owned' whitepaper) and Shadow Credentials / Key Trust abuse — and confirms both vectors are in active use by financially-motivated ransomware crews and state-sponsored intrusion sets. ESC1 (the canonical certificate template misconfiguration) requires a template that (a) permits client authentication EKUs, (b) allows the requester to supply the Subject Alternative Name (msPKI-Certificate-Name-Flag = ENROLLEE_SUPPLIES_SUBJECT / CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT 0x1), (c) does not require manager approval, and (d) is published on an Enterprise CA with broad enrollment rights. An attacker with enrollment rights requests a certificate while setting the SAN to a high-privilege UPN (e.g. Domain Admin or krbtgt), then uses PKINITtools / Rubeus to perform PKINIT authentication with the resulting certificate, receiving a TGT as the impersonated principal. Certify (.NET) and Certipy (Python) are the de facto offensive tooling — Certipy 4.x supports ESC1 through ESC16 enumeration and exploitation in a single binary. Shadow Credentials abuse the msDS-KeyCredentialLink attribute introduced for Windows Hello for Business Key Trust. Any principal with GenericWrite or GenericAll over a target object (user or computer) can write a self-generated public key into the target's msDS-KeyCredentialLink, then authenticate as that target via PKINIT — effectively persistent credential theft without a password reset and without triggering DCSync. The Whisker (.NET) and pyWhisker tools automate the attack chain. CVE-2022-26923 ('Certifried', disclosed by Oliver Lyak / IFsec Labs and patched May 2022) is the underlying domain controller validation flaw that elevated these primitives to full domain compromise. Prior to KB5014754, certificate-based authentication mapped UPN/dNSHostName from the certificate to an AD object without strong binding — an authenticated user who controlled a computer account (default MachineAccountQuota = 10 in most domains) could set its dNSHostName to that of a domain controller, request a certificate via the default Machine template, and authenticate as the DC. The fix introduced strong certificate mapping via the SID security extension (szOID_NTDS_CA_SECURITY_EXT) and Full Enforcement Mode enabled by default in February 2025 (KB5014754 timeline). Active exploitation has been documented across the threat landscape. The DFIR Report's Fog ransomware case studies (2024–2025) detail post-compromise tradecraft where affiliates pivot from initial access (often SonicWall SSL VPN CVE-2024-40766 or Veeam CVE-2024-40711) into Certipy enumeration, identify a vulnerable ESC1 template, mint a certificate as Domain Admin, perform DCSync, and deploy Fog ransomware. Rapid7's August 2024 IR engagement (referenced by Unit 42) documented a social-engineering campaign delivering update6.exe — a wrapper that attempted CVE-2022-26923 exploitation against unpatched domains. Palo Alto attributes parallel AD CS abuse to Fighting Ursa (overlapping with Microsoft's Forest Blizzard and CrowdStrike's Fancy Bear — GRU Unit 26165 / APT28), targeting government, defense, and energy verticals in Europe and North America. Detection is constrained because the underlying Windows events (4768 TGT request, 4886 certificate issuance, 4887 CA certificate request approved) are high-volume and lack native correlation with anomalous SANs or KeyCredentialLink modifications. Defenders should baseline 4886/4887 by template, alert on issuance of certificates with mismatched SAN UPNs, monitor msDS-KeyCredentialLink writes (4662 with the appropriate property GUID 5b47d60f-6090-40b2-9f37-2a4de88f3063), and enforce KB5014754 Full Enforcement Mode. Microsoft's StrongCertificateBindingEnforcement registry key under HKLM\SYSTEM\CurrentControlSet\Services\Kdc must be set to 2 (Full Enforcement).
MITRE ATT&CK techniques used in TL-2026-0497
Credential Access
T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets; T1606 Forge Web Credentials; T1649 Steal or Forge Authentication Certificates
Lateral Movement
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1098 Account Manipulation; T1136 Create Account
Collection
T1213 Data from Information Repositories
Impact
T1486 Data Encrypted for Impact
lateral-movement
T1550 Use Alternate Authentication Material
defense-impairment
Affected products and versions in Unit 42 Deep Dive
- Microsoft — Active Directory Domain Services
Vulnerable versions: Windows Server 2008 R2; Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022
Fixed in: All supported versions with KB5014754 (May 2022) plus February 2025 Full Enforcement Mode - Microsoft — Active Directory Certificate Services
Vulnerable versions: All Enterprise CA deployments with misconfigured certificate templates (ESC1-ESC16)
Fixed in: Hardened template configurations; templates audited per SpecterOps guidance - Microsoft — Windows Domain Controller
Vulnerable versions: Domain Controllers running KDC without StrongCertificateBindingEnforcement Full Enforcement
Fixed in: DCs with StrongCertificateBindingEnforcement = 2 and KB5014754 applied
Remediation for Unit 42 Deep Dive
Patches
- Apply Windows KB5014754 (May 10, 2022) to all domain controllers — addresses CVE-2022-26923
- Apply February 2025 update enabling Full Enforcement Mode by default
- Apply KB5019966/KB5020805 series cumulative updates for certificate mapping hardening
Immediate actions
- Enable StrongCertificateBindingEnforcement Full Enforcement Mode (HKLM\SYSTEM\CurrentControlSet\Services\Kdc\StrongCertificateBindingEnforcement = 2)
- Audit all certificate templates for ENROLLEE_SUPPLIES_SUBJECT flag combined with Client Authentication EKU and broad enrollment rights — remove or restrict immediately
- Set MachineAccountQuota to 0 via Default Domain Controllers Policy to prevent computer-account-based ESC primitives
- Disable msDS-KeyCredentialLink writes from non-privileged principals; audit existing values on Tier 0 assets and remove stale entries
- Run Certipy 'find -vulnerable' or Locksmith against the environment to identify ESC1-ESC16 exposures before adversaries do
Workarounds
- If immediate patching is not possible, manually configure StrongCertificateBindingEnforcement registry value to 1 (Compatibility) and prepare for 2 (Full Enforcement)
- Block PKINIT pre-authentication for service accounts that do not require certificate logon
- Restrict 'Enroll' and 'Autoenroll' permissions on all templates to specifically scoped groups (no Authenticated Users, Domain Users, or Domain Computers)
Longer-term hardening
- Deploy ADCS-specific SIEM content for Event IDs 4886, 4887, 4768 with certificate template and SAN context
- Implement tiered administration with PAW workstations for CA management; remove CA admin rights from Tier 1/2 accounts
- Migrate to short-lived (24-hour) certificates with automatic enrollment, eliminating long-lived credentials
- Establish CA-specific HSM-backed signing keys and offline root CA architecture
- Conduct quarterly purple team exercises targeting ESC1, ESC4, ESC8 (NTLM relay to AD CS), and Shadow Credentials
CVEs associated with Unit 42 Deep Dive
Weaknesses (CWE) in Unit 42 Deep Dive
CWE-295, CWE-287, CWE-269
Timeline of Unit 42 Deep Dive
- SpecterOps researchers Will Schroeder and Lee Christensen publish 'Certified Pre-Owned' whitepaper introducing ESC1-ESC8 taxonomy for AD CS abuse
- Dirk-jan Mollema releases PKINITtools providing Linux PKINIT authentication primitives enabling Certipy ecosystem
- Elad Shamir releases Whisker .NET tool automating msDS-KeyCredentialLink (Shadow Credentials) abuse
- Microsoft discloses CVE-2022-26923 ('Certifried') with CVSS 8.8 and releases KB5014754 introducing certificate mapping hardening
- Oliver Lyak releases Certipy 4.0 supporting ESC1-ESC11 enumeration and exploitation in a single Python binary
- CISA adds CVE-2022-26923 to the Known Exploited Vulnerabilities catalog with September 8, 2022 federal remediation deadline
- Rapid7 incident response documents social-engineering campaign delivering update6.exe wrapper that attempted CVE-2022-26923 exploitation against unpatched victim domains
- DFIR Report publishes Fog ransomware case study detailing Certipy-based ESC1 abuse for post-compromise privilege escalation to domain admin
- Microsoft enables StrongCertificateBindingEnforcement Full Enforcement Mode by default on supported Windows domain controllers, closing CVE-2022-26923 attack path for patched environments
- Unit 42 telemetry attributes ongoing AD CS template abuse and Shadow Credentials operations to Fighting Ursa (APT28 / Forest Blizzard / GRU Unit 26165) targeting European defense and energy sectors
- Unit 42 publishes consolidated AD CS exploitation deep-dive cataloguing ESC1-ESC16 abuse, Shadow Credentials techniques, and confirming active financially-motivated and state-sponsored exploitation
- As of 2026-05-29, AD CS abuse (ESC1, Shadow Credentials, ESC1-ESC16) remains actively exploited via maintained tooling (Certipy/Certify/Whisker) by Fog ransomware and APT28/Fighting Ursa, who run live 2026 campaigns. CVE-2022-26923 is patched (KB5014754, Feb 2025 Full Enforcement) yet stays in CISA KEV; the config-driven attack surface is unpatchable and persists.
Sources cited for Unit 42 Deep Dive
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools (Unit 42)
- Certified Pre-Owned: Abusing Active Directory Certificate Services (SpecterOps)
- MSRC CVE-2022-26923 Security Advisory
- CISA Known Exploited Vulnerabilities — CVE-2022-26923
- NVD CVE-2022-26923
- Certipy — AD CS Enumeration and Abuse Tool
- Certify — .NET AD CS Tool (GhostPack)
- Whisker — Shadow Credentials Tool (Eladshamir)
- pyWhisker — Python Shadow Credentials
- PKINITtools — Linux PKINIT Implementation (dirkjanm)
- The DFIR Report: Fog Ransomware Cases (AD CS Abuse Chains)
- Rapid7 IR Disclosure: update6.exe Social Engineering Campaign Targeting CVE-2022-26923
- KB5014754 — Certificate-based authentication changes on Windows domain controllers
- MITRE ATT&CK T1649 Steal or Forge Authentication Certificates
- Locksmith — AD CS Defensive Audit Tool
Threats related to Unit 42 Deep Dive
Detection coverage for TL-2026-0497
As of 2026-05-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0497 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.