Andariel 공격 그룹이 활용하는 RID Hijacking 공격 기법

2025-01-22 Ahnlab RID Hijacking Attack Technique Used by the Andariel Attack Group

https://asec.ahnlab.com/ko/85920/

Thumbnail for Andariel 공격 그룹이 활용하는 RID Hijacking 공격 기법

AhnLab reports that the Andariel threat group used RID Hijacking during intrusions to manipulate Windows account relative identifier values and elevate privileges. The technique can make a limited or guest account inherit administrator-like access, supporting persistence and stealth after compromise. The report links the behavior to Andariel operations involving malicious files and backdoor account creation, giving defenders concrete Windows account-abuse tradecraft to hunt.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back