Threat reportThreat IntelligenceTL-2026-2174
Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting
Ghost SPN: Active Directory SPN Misconfigurations Enable (TL-2026-2174), also tracked as Ghost SPN, is a high-severity tracked intrusion set, first published 2026-08-28. It has no confirmed attribution, affects Microsoft Active Directory Domain Services (Kerberos authentication), maps to 8 MITRE ATT&CK techniques (T1003.001, T1078.002, T1087.002), and is covered by 9 detection rules and 7 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-2174
- Threat ID
- TL-2026-2174
- Also known as
- Ghost SPN
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Ghost SPN: Active Directory SPN Misconfigurations Enable
Malware and tooling: MimiKatz, Hashcat, Mimikatz, PowerView, Rubeus - S1071, tgsrepcrack.py
How Ghost SPN: Active Directory SPN Misconfigurations Enable works
Trellix researchers documented 'Ghost SPN,' a Kerberoasting variant in which an attacker with delegated Active Directory write access (e.g. GenericAll/WriteSPN) temporarily assigns a Service Principal Name to a standard user account, requests an RC4-HMAC-encrypted Kerberos TGS ticket for fast offline cracking, then removes the SPN to erase the modification trail before defenders notice.
Ghost SPN is a stealthier evolution of Kerberoasting first documented by Trellix in a series of 2025-2026 research posts ('When SPNs Go Rogue,' 'The Ghost SPN Attack,' and 'Now You See It, Now You Don't') and independently covered by Cyber Security News. Unlike classic Kerberoasting, which targets pre-existing service accounts that already carry a persistent SPN, Ghost SPN converts an ordinary, non-service user account into an ephemeral Kerberoasting target that exists only for the duration of the attack, generating zero enumeration-based alerts because no known service account is ever touched.
The attack proceeds in four observable phases. First, the attacker enumerates the domain for accounts already bearing an SPN to understand the legitimate baseline (and, more broadly, Kerberoastable-account discovery in this technique class is performed with tooling such as PowerView, Impacket's GetUserSPNs, raw LDAP queries, or Rubeus). Second, an attacker who holds over-delegated Active Directory permissions (commonly GenericAll object-level write access or the narrower WriteSPN right on user objects) writes an arbitrary Service Principal Name (e.g. 'http/webapp') to the msDS-ServicePrincipalName attribute of a standard user account out-of-band, i.e. outside any legitimate service-provisioning workflow, typically via native AD administration surfaces (PowerShell's Set-ADUser -ServicePrincipalNames cmdlet or the legacy setspn.exe). Third, the attacker requests a Kerberos Ticket Granting Service (TGS) ticket for the now-SPN-bearing account, deliberately favoring the legacy RC4-HMAC-MD5 (etype 0x17/0x23) encryption type over AES because its password-derived key can be brute-forced far more efficiently offline -- Trellix's detection tooling explicitly flags this cipher choice as an 'encryption downgrade' behavioral indicator (MITRE ATT&CK T1562.010, Impair Defenses: Downgrade Attack). The ticket is dumped from memory with credential-access tooling such as Mimikatz, exported as a .kirbi file, and cracked entirely outside the target environment using Hashcat or tgsrepcrack.py, generating no authentication failures on the wire; Cyber Security News additionally reports the extracted ticket may be reused directly for pass-the-ticket lateral movement (T1550.003) rather than only cracked offline. Fourth, the attacker immediately clears the SPN attribute, restoring the account to its pre-attack state and eliminating the persistent directory indicator that would otherwise let defenders retroactively spot an anomalous service account.
Because the technique abuses legitimate Kerberos and Active Directory administrative functionality rather than any software vulnerability, it produces minimal authentication-log noise and directly undermines detection models built on two flawed assumptions: that Kerberoasting targets are always pre-registered service accounts, and that malicious ticket requests always produce high-volume, baseline-deviating anomalies. Trellix's own detection approach (delivered via Trellix NDR) instead correlates three signals: msDS-ServicePrincipalName attribute changes against subsequent Kerberos TGS requests, encryption-type downgrades on those requests, and suspicious timing (an account modification occurring mere seconds before its first-ever service-ticket request). This complements MITRE ATT&CK's own published Kerberoasting detection strategy (DET0157 / analytic AN0444, created 2025-10-21 and last revised 2026-05-12), which recommends monitoring Event ID 4769 TGS requests using RC4 encryption together with Sysmon Event ID 10 LSASS process-access telemetry and logon-session data (Event IDs 4624, 4648, 4672) to catch accounts requesting an unusual volume of service tickets outside their baseline.
There is no CVE associated with this Ghost SPN Kerberoasting variant; it is a misconfiguration/tradecraft issue rooted in over-permissive AD delegation (GenericAll/WriteSPN) and RC4-HMAC being enabled by default, not a patchable software flaw. (Note: a separate, unrelated 'Ghost SPN' concept -- SPNs that reference DNS-unresolvable hostnames, abused for Kerberos-relay privilege escalation and tracked as CVE-2025-58726 in Semperis research -- shares only the name; it is a distinct attack chain against computer accounts, not this user-account Kerberoasting technique, and is referenced here only as related background, not as part of this threat's chain.) No confirmed multi-victim active-exploitation campaign has been reported; Trellix's coverage documents the technique and detection approach rather than an observed intrusion.
MITRE ATT&CK techniques used in TL-2026-2174
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1110.002 Brute Force: Password Cracking; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
Initial Access
T1078.002 Valid Accounts: Domain Accounts
Privilege Escalation
T1078.002 Valid Accounts: Domain Accounts
Discovery
T1087.002 Account Discovery: Domain Account
Persistence
Lateral Movement
T1550.003 Use Alternate Authentication Material: Pass the Ticket
defense-impairment
Affected products and versions in Ghost SPN: Active Directory SPN Misconfigurations Enable
- Microsoft — Active Directory Domain Services (Kerberos authentication)
Vulnerable versions: Any AD DS environment with RC4-HMAC Kerberos encryption enabled (Microsoft default) combined with over-permissive delegated write access (GenericAll/WriteSPN) on user objects
Fixed in: No vendor patch applicable; mitigated by enforcing AES-only Kerberos encryption, migrating service identities to gMSA, and auditing/restricting delegated SPN-write permissions
Remediation for Ghost SPN: Active Directory SPN Misconfigurations Enable
Immediate actions
- Audit and revoke GenericAll or WriteSPN delegated permissions held by non-administrative accounts on user objects
- Enable granular Active Directory change auditing that correlates msDS-ServicePrincipalName attribute modifications with downstream Kerberos TGS requests
- Deploy honey-token SPN accounts to generate high-fidelity alerts on any Kerberoasting-style enumeration or ticket request
Workarounds
- Reset passwords for any account with historical write-access exposure to the servicePrincipalName attribute
- Restrict SPN-write delegation to dedicated service-account management groups rather than broad administrative roles
Longer-term hardening
- Migrate service accounts to group Managed Service Accounts (gMSA) with automatically rotated, randomized passwords
- Enforce AES-only Kerberos encryption domain-wide and disable RC4-HMAC where compatibility permits
- Deploy behavioral Network Detection and Response (NDR) tooling capable of correlating cross-domain AD and Kerberos telemetry, including encryption-downgrade and timing anomalies
Timeline of Ghost SPN: Active Directory SPN Misconfigurations Enable
- MITRE ATT&CK publishes Detection Strategy DET0157 / Analytic AN0444 for Kerberoasting (T1558.003), the RC4-etype TGS-request and LSASS-access correlation logic later cited alongside Ghost SPN coverage.
- Trellix publishes 'When SPNs Go Rogue: Detection and Remediation with Trellix NDR,' documenting how SPN misconfigurations on standard user accounts enable Kerberoasting.
- Trellix publishes 'The Ghost SPN Attack: Catching Stealthy Kerberoasting Before It's Too Late Using Trellix NDR,' naming and detailing the ephemeral-SPN Kerberoasting variant 'Ghost SPN.'
- Cyber Security News publishes 'Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar,' summarizing the Trellix research for a wider audience.
- MITRE ATT&CK last-revises Detection Strategy DET0157, the Kerberoasting detection logic underpinning cross-referenced defensive guidance for the technique class.
- Trellix publishes a follow-up post, 'Now You See It, Now You Don't: Inside the Ghost SPN Attack Bypassing Your Security,' further detailing detection evasion, encryption-downgrade indicators, and defense recommendations.
- Cyber Security News re-covers the technique in 'Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks,' additionally reporting pass-the-ticket reuse of the extracted TGS ticket; this is the article that triggered this threat's tracking.
Sources cited for Ghost SPN: Active Directory SPN Misconfigurations Enable
- Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks
- Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar
- The Ghost SPN Attack: Catching Stealthy Kerberoasting Before It's Too Late Using Trellix NDR
- Now You See It, Now You Don't: Inside the Ghost SPN Attack Bypassing Your Security
- When SPNs Go Rogue: Detection and Remediation with Trellix NDR
- Steal or Forge Kerberos Tickets: Kerberoasting, Sub-technique T1558.003 - Enterprise | MITRE ATT&CK
- Detect Kerberoasting Attempts (T1558.003), Detection Strategy DET0157 | MITRE ATT&CK
- Use Alternate Authentication Material: Pass the Ticket, Sub-technique T1550.003 | MITRE ATT&CK
- Impair Defenses: Downgrade Attack, Sub-technique T1562.010 | MITRE ATT&CK
- Exploiting Ghost SPNs and Kerberos Reflection for SMB Server Privilege Elevation
- What is Kerberoasting?
Detection coverage for TL-2026-2174
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2174 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.