# Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting

> Trellix researchers documented 'Ghost SPN,' a Kerberoasting variant in which an attacker with delegated Active Directory write access (e.g. GenericAll/WriteSPN) temporarily assigns a Service Principal Name to a standard user account, requests an RC4-HMAC-encrypted Kerberos TGS ticket for fast offline cracking, then removes the SPN to erase the modification trail before defenders notice.

- **Published:** 2026-08-28T00:00:00Z
- **Last reviewed:** 2026-08-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2174
- **ID:** TL-2026-2174
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Ghost SPN is a stealthier evolution of Kerberoasting first documented by Trellix in a series of 2025-2026 research posts ('When SPNs Go Rogue,' 'The Ghost SPN Attack,' and 'Now You See It, Now You Don't') and independently covered by Cyber Security News. Unlike classic Kerberoasting, which targets pre-existing service accounts that already carry a persistent SPN, Ghost SPN converts an ordinary, non-service user account into an ephemeral Kerberoasting target that exists only for the duration of the attack, generating zero enumeration-based alerts because no known service account is ever touched.

The attack proceeds in four observable phases. First, the attacker enumerates the domain for accounts already bearing an SPN to understand the legitimate baseline (and, more broadly, Kerberoastable-account discovery in this technique class is performed with tooling such as PowerView, Impacket's GetUserSPNs, raw LDAP queries, or Rubeus). Second, an attacker who holds over-delegated Active Directory permissions (commonly GenericAll object-level write access or the narrower WriteSPN right on user objects) writes an arbitrary Service Principal Name (e.g. 'http/webapp') to the msDS-ServicePrincipalName attribute of a standard user account out-of-band, i.e. outside any legitimate service-provisioning workflow, typically via native AD administration surfaces (PowerShell's Set-ADUser -ServicePrincipalNames cmdlet or the legacy setspn.exe). Third, the attacker requests a Kerberos Ticket Granting Service (TGS) ticket for the now-SPN-bearing account, deliberately favoring the legacy RC4-HMAC-MD5 (etype 0x17/0x23) encryption type over AES because its password-derived key can be brute-forced far more efficiently offline -- Trellix's detection tooling explicitly flags this cipher choice as an 'encryption downgrade' behavioral indicator (MITRE ATT&CK T1562.010, Impair Defenses: Downgrade Attack). The ticket is dumped from memory with credential-access tooling such as Mimikatz, exported as a .kirbi file, and cracked entirely outside the target environment using Hashcat or tgsrepcrack.py, generating no authentication failures on the wire; Cyber Security News additionally reports the extracted ticket may be reused directly for pass-the-ticket lateral movement (T1550.003) rather than only cracked offline. Fourth, the attacker immediately clears the SPN attribute, restoring the account to its pre-attack state and eliminating the persistent directory indicator that would otherwise let defenders retroactively spot an anomalous service account.

Because the technique abuses legitimate Kerberos and Active Directory administrative functionality rather than any software vulnerability, it produces minimal authentication-log noise and directly undermines detection models built on two flawed assumptions: that Kerberoasting targets are always pre-registered service accounts, and that malicious ticket requests always produce high-volume, baseline-deviating anomalies. Trellix's own detection approach (delivered via Trellix NDR) instead correlates three signals: msDS-ServicePrincipalName attribute changes against subsequent Kerberos TGS requests, encryption-type downgrades on those requests, and suspicious timing (an account modification occurring mere seconds before its first-ever service-ticket request). This complements MITRE ATT&CK's own published Kerberoasting detection strategy (DET0157 / analytic AN0444, created 2025-10-21 and last revised 2026-05-12), which recommends monitoring Event ID 4769 TGS requests using RC4 encryption together with Sysmon Event ID 10 LSASS process-access telemetry and logon-session data (Event IDs 4624, 4648, 4672) to catch accounts requesting an unusual volume of service tickets outside their baseline.

There is no CVE associated with this Ghost SPN Kerberoasting variant; it is a misconfiguration/tradecraft issue rooted in over-permissive AD delegation (GenericAll/WriteSPN) and RC4-HMAC being enabled by default, not a patchable software flaw. (Note: a separate, unrelated 'Ghost SPN' concept -- SPNs that reference DNS-unresolvable hostnames, abused for Kerberos-relay privilege escalation and tracked as CVE-2025-58726 in Semperis research -- shares only the name; it is a distinct attack chain against computer accounts, not this user-account Kerberoasting technique, and is referenced here only as related background, not as part of this threat's chain.) No confirmed multi-victim active-exploitation campaign has been reported; Trellix's coverage documents the technique and detection approach rather than an observed intrusion.

## MITRE ATT&CK

- T1087.002 Account Discovery: Domain Account
- T1098 Account Manipulation
- T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
- T1110.002 Brute Force: Password Cracking
- T1003.001 OS Credential Dumping: LSASS Memory
- T1689 Downgrade Attack
- T1078.002 Valid Accounts: Domain Accounts
- T1078.002 Valid Accounts: Domain Accounts
- T1550.003 Use Alternate Authentication Material: Pass the Ticket

## Sources

- [Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks](https://cybersecuritynews.com/active-directory-spn-misconfigurations/)
- [Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar](https://cybersecuritynews.com/ghost-spn-attack/)
- [The Ghost SPN Attack: Catching Stealthy Kerberoasting Before It's Too Late Using Trellix NDR](https://www.trellix.com/blogs/research/ghost-spn-attack-kerberoasting-detection-trellix-ndr/)
- [Now You See It, Now You Don't: Inside the Ghost SPN Attack Bypassing Your Security](https://www.trellix.com/blogs/platform/the-ghost-spn-attack-bypassing-your-security/)
- [When SPNs Go Rogue: Detection and Remediation with Trellix NDR](https://www.trellix.com/blogs/research/spns-go-rogue-detection-remediation-with-trellix-ndr/)
- [Steal or Forge Kerberos Tickets: Kerberoasting, Sub-technique T1558.003 - Enterprise | MITRE ATT&CK](https://attack.mitre.org/techniques/T1558/003/)
- [Detect Kerberoasting Attempts (T1558.003), Detection Strategy DET0157 | MITRE ATT&CK](https://attack.mitre.org/detectionstrategies/DET0157/)
- [Use Alternate Authentication Material: Pass the Ticket, Sub-technique T1550.003 | MITRE ATT&CK](https://attack.mitre.org/techniques/T1550/003/)
- [Impair Defenses: Downgrade Attack, Sub-technique T1562.010 | MITRE ATT&CK](https://attack.mitre.org/techniques/T1562/010/)
- [Exploiting Ghost SPNs and Kerberos Reflection for SMB Server Privilege Elevation](https://www.semperis.com/blog/exploiting-ghost-spns-and-kerberos-reflection-for-smb-server-privilege-elevation/)
- [What is Kerberoasting?](https://redcanary.com/blog/threat-detection/marshmallows-and-kerberoasting/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2174
