Threat reportThreat IntelligenceTL-2026-2174

Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting

highACTIVE

Ghost SPN: Active Directory SPN Misconfigurations Enable (TL-2026-2174), also tracked as Ghost SPN, is a high-severity tracked intrusion set, first published 2026-08-28. It has no confirmed attribution, affects Microsoft Active Directory Domain Services (Kerberos authentication), maps to 8 MITRE ATT&CK techniques (T1003.001, T1078.002, T1087.002), and is covered by 9 detection rules and 7 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-2174

Threat ID
TL-2026-2174
Also known as
Ghost SPN
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
7

Malware and tooling in Ghost SPN: Active Directory SPN Misconfigurations Enable

Malware and tooling: MimiKatz, Hashcat, Mimikatz, PowerView, Rubeus - S1071, tgsrepcrack.py

How Ghost SPN: Active Directory SPN Misconfigurations Enable works

Trellix researchers documented 'Ghost SPN,' a Kerberoasting variant in which an attacker with delegated Active Directory write access (e.g. GenericAll/WriteSPN) temporarily assigns a Service Principal Name to a standard user account, requests an RC4-HMAC-encrypted Kerberos TGS ticket for fast offline cracking, then removes the SPN to erase the modification trail before defenders notice.

Ghost SPN is a stealthier evolution of Kerberoasting first documented by Trellix in a series of 2025-2026 research posts ('When SPNs Go Rogue,' 'The Ghost SPN Attack,' and 'Now You See It, Now You Don't') and independently covered by Cyber Security News. Unlike classic Kerberoasting, which targets pre-existing service accounts that already carry a persistent SPN, Ghost SPN converts an ordinary, non-service user account into an ephemeral Kerberoasting target that exists only for the duration of the attack, generating zero enumeration-based alerts because no known service account is ever touched.

The attack proceeds in four observable phases. First, the attacker enumerates the domain for accounts already bearing an SPN to understand the legitimate baseline (and, more broadly, Kerberoastable-account discovery in this technique class is performed with tooling such as PowerView, Impacket's GetUserSPNs, raw LDAP queries, or Rubeus). Second, an attacker who holds over-delegated Active Directory permissions (commonly GenericAll object-level write access or the narrower WriteSPN right on user objects) writes an arbitrary Service Principal Name (e.g. 'http/webapp') to the msDS-ServicePrincipalName attribute of a standard user account out-of-band, i.e. outside any legitimate service-provisioning workflow, typically via native AD administration surfaces (PowerShell's Set-ADUser -ServicePrincipalNames cmdlet or the legacy setspn.exe). Third, the attacker requests a Kerberos Ticket Granting Service (TGS) ticket for the now-SPN-bearing account, deliberately favoring the legacy RC4-HMAC-MD5 (etype 0x17/0x23) encryption type over AES because its password-derived key can be brute-forced far more efficiently offline -- Trellix's detection tooling explicitly flags this cipher choice as an 'encryption downgrade' behavioral indicator (MITRE ATT&CK T1562.010, Impair Defenses: Downgrade Attack). The ticket is dumped from memory with credential-access tooling such as Mimikatz, exported as a .kirbi file, and cracked entirely outside the target environment using Hashcat or tgsrepcrack.py, generating no authentication failures on the wire; Cyber Security News additionally reports the extracted ticket may be reused directly for pass-the-ticket lateral movement (T1550.003) rather than only cracked offline. Fourth, the attacker immediately clears the SPN attribute, restoring the account to its pre-attack state and eliminating the persistent directory indicator that would otherwise let defenders retroactively spot an anomalous service account.

Because the technique abuses legitimate Kerberos and Active Directory administrative functionality rather than any software vulnerability, it produces minimal authentication-log noise and directly undermines detection models built on two flawed assumptions: that Kerberoasting targets are always pre-registered service accounts, and that malicious ticket requests always produce high-volume, baseline-deviating anomalies. Trellix's own detection approach (delivered via Trellix NDR) instead correlates three signals: msDS-ServicePrincipalName attribute changes against subsequent Kerberos TGS requests, encryption-type downgrades on those requests, and suspicious timing (an account modification occurring mere seconds before its first-ever service-ticket request). This complements MITRE ATT&CK's own published Kerberoasting detection strategy (DET0157 / analytic AN0444, created 2025-10-21 and last revised 2026-05-12), which recommends monitoring Event ID 4769 TGS requests using RC4 encryption together with Sysmon Event ID 10 LSASS process-access telemetry and logon-session data (Event IDs 4624, 4648, 4672) to catch accounts requesting an unusual volume of service tickets outside their baseline.

There is no CVE associated with this Ghost SPN Kerberoasting variant; it is a misconfiguration/tradecraft issue rooted in over-permissive AD delegation (GenericAll/WriteSPN) and RC4-HMAC being enabled by default, not a patchable software flaw. (Note: a separate, unrelated 'Ghost SPN' concept -- SPNs that reference DNS-unresolvable hostnames, abused for Kerberos-relay privilege escalation and tracked as CVE-2025-58726 in Semperis research -- shares only the name; it is a distinct attack chain against computer accounts, not this user-account Kerberoasting technique, and is referenced here only as related background, not as part of this threat's chain.) No confirmed multi-victim active-exploitation campaign has been reported; Trellix's coverage documents the technique and detection approach rather than an observed intrusion.

MITRE ATT&CK techniques used in TL-2026-2174

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1110.002 Brute Force: Password Cracking; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting

Initial Access

T1078.002 Valid Accounts: Domain Accounts

Privilege Escalation

T1078.002 Valid Accounts: Domain Accounts

Discovery

T1087.002 Account Discovery: Domain Account

Persistence

T1098 Account Manipulation

Lateral Movement

T1550.003 Use Alternate Authentication Material: Pass the Ticket

defense-impairment

T1689 Downgrade Attack

Affected products and versions in Ghost SPN: Active Directory SPN Misconfigurations Enable

  • Microsoft — Active Directory Domain Services (Kerberos authentication)
    Vulnerable versions: Any AD DS environment with RC4-HMAC Kerberos encryption enabled (Microsoft default) combined with over-permissive delegated write access (GenericAll/WriteSPN) on user objects
    Fixed in: No vendor patch applicable; mitigated by enforcing AES-only Kerberos encryption, migrating service identities to gMSA, and auditing/restricting delegated SPN-write permissions

Remediation for Ghost SPN: Active Directory SPN Misconfigurations Enable

Immediate actions

  • Audit and revoke GenericAll or WriteSPN delegated permissions held by non-administrative accounts on user objects
  • Enable granular Active Directory change auditing that correlates msDS-ServicePrincipalName attribute modifications with downstream Kerberos TGS requests
  • Deploy honey-token SPN accounts to generate high-fidelity alerts on any Kerberoasting-style enumeration or ticket request

Workarounds

  • Reset passwords for any account with historical write-access exposure to the servicePrincipalName attribute
  • Restrict SPN-write delegation to dedicated service-account management groups rather than broad administrative roles

Longer-term hardening

  • Migrate service accounts to group Managed Service Accounts (gMSA) with automatically rotated, randomized passwords
  • Enforce AES-only Kerberos encryption domain-wide and disable RC4-HMAC where compatibility permits
  • Deploy behavioral Network Detection and Response (NDR) tooling capable of correlating cross-domain AD and Kerberos telemetry, including encryption-downgrade and timing anomalies

Timeline of Ghost SPN: Active Directory SPN Misconfigurations Enable

  • MITRE ATT&CK publishes Detection Strategy DET0157 / Analytic AN0444 for Kerberoasting (T1558.003), the RC4-etype TGS-request and LSASS-access correlation logic later cited alongside Ghost SPN coverage.
  • Trellix publishes 'When SPNs Go Rogue: Detection and Remediation with Trellix NDR,' documenting how SPN misconfigurations on standard user accounts enable Kerberoasting.
  • Trellix publishes 'The Ghost SPN Attack: Catching Stealthy Kerberoasting Before It's Too Late Using Trellix NDR,' naming and detailing the ephemeral-SPN Kerberoasting variant 'Ghost SPN.'
  • Cyber Security News publishes 'Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar,' summarizing the Trellix research for a wider audience.
  • MITRE ATT&CK last-revises Detection Strategy DET0157, the Kerberoasting detection logic underpinning cross-referenced defensive guidance for the technique class.
  • Trellix publishes a follow-up post, 'Now You See It, Now You Don't: Inside the Ghost SPN Attack Bypassing Your Security,' further detailing detection evasion, encryption-downgrade indicators, and defense recommendations.
  • Cyber Security News re-covers the technique in 'Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks,' additionally reporting pass-the-ticket reuse of the extracted TGS ticket; this is the article that triggered this threat's tracking.

Sources cited for Ghost SPN: Active Directory SPN Misconfigurations Enable

Detection coverage for TL-2026-2174

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2174 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats