SSO, IdP, or federation compromise
Kerberoasting
Kerberoasting is an Active Directory attack in which any signed-in domain user requests Kerberos service tickets for service accounts, then cracks those tickets offline to recover the accounts' passwords. It needs no special rights to start, and service accounts with weak, old passwords and high privileges are the usual prize.
How it works
The attacker lists accounts that have a service principal name, asks the domain controller for a ticket for each, and saves the tickets. Part of each ticket is encrypted with the service account's password hash, so it can be brute-forced on the attacker's own hardware. Cracking happens offline, so it triggers no lockouts.
A real example
The FBI and CISA's Cuba ransomware advisory said the actors used a PowerShell script to target service accounts for their Active Directory Kerberos tickets, then collected and cracked the tickets offline via Kerberoasting.
Source: #StopRansomware: Cuba Ransomware (AA22-335A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-12-01
How to stop it
Give service accounts long random passwords or managed service accounts, remove unneeded service principal names, use AES encryption for tickets, and alert on bursts of service ticket requests.
Related terms
Threat actors that use it
- Akira
Profile with government sources
Sources
- #StopRansomware: Cuba Ransomware (AA22-335A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-12-01
Last reviewed Oct 2, 2026