RID Hijacking Technique Utilized by Andariel Attack Group
2025-01-24 • Ahnlab •
AhnLab reports that Andariel used malicious files and a CreateHiddenAccount-style tool to perform RID hijacking during Windows intrusions. The technique modifies SAM registry values so a low-privilege or newly created hidden account is treated as having the RID of an administrator account, enabling privilege escalation and stealthy persistence. The observed chain used SYSTEM-level execution through tools such as PsExec, account creation with a trailing dollar sign, Remote Desktop Users and Administrators group membership, registry export and reimport, and hardcoded behavior tailored to the victim environment.
Related Actors
Related Reports
Shares tag: Andariel • Same author: Ahnlab • Published within a week
2025-01-02 •
90% Match
#Andariel
#Ransomware
#Play
#T1046
#T1219
#T1562.001
#T1486
#T1018
#T1657
#T1003.001
#T1048.003
#T1560.001
#T1033
#T1087.002
#T1570
#T1069.001
#T1069.002
#T1572
#T1615
#T1482
Shares tag: Andariel • Same author: Ahnlab • Published within a month
2025-01-01 •
90% Match
#Andariel
#Ransomware
#Play
#T1046
#T1219
#T1562.001
#T1486
#T1018
#T1657
#T1003.001
#T1048.003
#T1560.001
#T1033
#T1087.002
#T1570
#T1069.001
#T1069.002
#T1572
#T1615
#T1482
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Published within a week
Shares tag: Andariel • Published within a week
2025-01-20 •
80% Match
An exploratory analysis of the DPRK cyber threat landscape using publicly available reports
lazarusholic
Shares tag: Andariel • Published within a week