INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Advanced Malware Exploitation Techniques Used in AD CS Attacks

| 2026-05-11 22:00 CRITICAL HIGH
Executive Summary AI-generated
Adversaries have exploited vulnerabilities in native certificate issuance to impersonate privileged accounts and escalate privileges, with Unit 42 observations indicating that these weaknesses are actively used by both financially motivated ransomware groups and state-sponsored actors. These attacks typically involve misconfigured templates, overly permissive enrollment rights, and the misuse of native certificate issuance for account impersonation, allowing attackers to elevate their access levels within an enterprise through social engineering campaigns like the one described in August 2024, which exploited CVE-2022-26923.
Technical Mitigations AI-generated
• Implement secure certificate template management practices, including regular audits and updates to ensure templates are correctly configured. • Limit the privileges of AD CS administrators to prevent unauthorized access or escalation of privileges. • Regularly review and update AD CS policies and configurations to address known vulnerabilities and weaknesses.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28 CVE-2022-26923CVE-2022-26923
Target & Sectors
NORTH_AMERICA NORTH_AMERICA MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE
Incident Timeline
‎August 2024
Attackers used shadow credentials to gain stealthy, persistent access by exploiting low-privileged account requests for certificates from high-privileged templates.
tactic Social Engineering
vulnerability CVE-2022-26923
organisation CVE-2022
general_metric 26923 CVE-2022
organisation CSR
organisation Broad
infrastructure Windows
organisation Key Trust
organisation Windows Hello for Business
organisation Key Event
organisation Log Event ID Description Security
organisation Security 5136
organisation Microsoft
organisation Disable Windows Event Logging
organisation Certipy LDAP
organisation PKI-Enrollment-Service
organisation XDR Analytics BIOC
organisation Identity Analytics
organisation Suspicious
organisation XDR Analytics
organisation Certipy Certificate
organisation TGT
organisation Whisker Shadow
organisation CA
organisation EditFlags
organisation Schannel
organisation Cortex XDR/XSIAM
organisation Certified Pre-Owned:
organisation PDF
organisation SpecterOps
organisation ESC
organisation Requesters
organisation EKU
organisation Client Authentication
organisation Certipy
organisation Directory Modifications
organisation Active Directory
organisation Using Certify
organisation the Active Directory
organisation PKINITtools
organisation Behavioral Threat Protection
organisation Local Analysis
organisation Cortex
organisation Cloud Infrastructure Entitlement Management
organisation Identity Security Posture Management
organisation Data Access Governance
organisation DAG
organisation Identity Threat Detection
organisation ITDR
organisation Palo Alto Networks
organisation Cyber Threat Alliance
organisation CTA
organisation Cortex XDR AD CS Event Setup
threat_actor APT28
organisation ADExplorer
organisation Template Misuse – ESC Attacks Monitoring
organisation SAN
organisation Cortex XDR/XSIAM Alerts
organisation Identity Analytics Impair Defenses
‎2026/05/11
Threat actors used native certificate issuance to impersonate privileged accounts and escalate privileges in an ongoing AD CS escalation.
infrastructure Windows
organisation Active Directory Certificate Services
organisation PKI
organisation Cortex XDR
organisation XSIAM
organisation Cortex User Entity Behavior Analytics
organisation Cortex Cloud Identity Security
organisation Certificate
organisation Ongoing Exploitation and Blind Spots Despite
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product