Akira creates new local accounts for persistence and relies on Mimikatz, LaZagne, and Rubeus for credential theft.
Rubeus
Rubeus is an open-source C# toolkit for raw Kerberos interaction and abuse on Windows, particularly in Microsoft Active Directory environments.
Rubeus
Family profile
Rubeus is an open-source C# toolkit for raw Kerberos interaction and abuse on Windows, particularly in Microsoft Active Directory environments. It is a dual-use offensive security tool used by penetration testers and red teams and abused by threat actors for credential access and post-exploitation, rather than a standalone malware implant.
Its capabilities include Kerberoasting, extracting Kerberos tickets, submitting tickets to logon sessions for Pass-the-Ticket authentication, and forging and injecting Golden Tickets when the required KRBTGT key material is available. Kerberoasting obtains service-ticket material for offline password cracking. Its delegation functionality can retrieve a usable ticket-granting ticket for the current user through the Kerberos GSS-API without requiring local elevation. Ticket submission through native Windows authentication interfaces does not require directly opening LSASS, limiting visibility for detections focused on suspicious LSASS process access. These functions support impersonation, privilege escalation, and lateral movement within compromised domains.
Rubeus can execute as a Windows executable or be loaded into memory as a .NET assembly. It has been used in Akira ransomware intrusions and Earth Krahang espionage campaigns. QBot has also deployed Rubeus through injection into a legitimate Windows process; that injection is a deployment technique performed by QBot, not an intrinsic Rubeus capability.
Capabilities
- Credential Theft
- Lateral Movement
- Post Exploitation
- Privilege Escalation
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
7 named in public reporting"Rubeus uses the forged certificate to request a TGT as a Domain Admin."
Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.
The threat actor also used the Rubeus C# toolset for raw Kerberos interaction and abuse...
Rubeus, a C# based toolset for Kerberos interaction and abuse
“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”
“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”
Exploited software
Vulnerabilities linked to Rubeus
4 CVEsMITRE ATT&CK
Rubeus in ATT&CK
38 distinct techniquesTechniques
38 techniquesReporting
Research mentioning Rubeus
THREAT ANALYSIS: Cobalt Strike - IcedID, Emotet and QBot
Threat researchers reported that Emotet, IcedID, and QBot were used as initial access malware to quickly deliver Cobalt Strike on compromised Windows systems, sharply reducing the time defenders had to respond before hands-on-keyboard activity began. In observed intrusions, reconnaissance started within 6 to 8 minutes of infection, while Cobalt Strike was deployed in as little as under an hour to roughly two hours later. The activity was commonly initiated through targeted phishing emails carrying malicious Office documents and macros, with follow-on use of PowerShell, scheduled tasks, Run keys, or services to establish persistence and pull additional payloads.
APT techniques: Token theft via UpdateProcThreadAttribute. Simple C++ example. - cocomelonc
Security researchers detailed how attackers abuse Windows access tokens to impersonate users, elevate privileges, and move laterally across enterprise environments. The technique relies on the way Windows ties logon sessions, privileges, and cached credentials to access tokens, allowing an attacker with sufficient local rights to duplicate or impersonate another process token and launch a new process under that security context. One proof-of-concept shows a local administrator enabling SeDebugPrivilege, opening a privileged process such as winlogon.exe, duplicating its token, and using CreateProcessWithTokenW to spawn a process as SYSTEM. Additional analysis shows token manipulation extends beyond local privilege escalation into stealthier authentication abuse, including NETONLY logons, Pass-the-Hash, Pass-the-Ticket, and Overpass-the-Hash. Researchers said attackers can abuse Windows APIs such as LogonUserW, CreateProcessWithLogonW, DuplicateTokenEx, SetThreadToken, ImpersonateLoggedOnUser, and LsaCallAuthenticationPackage to create new logon sessions or alter authentication behavior without changing the visible local user context. Defenders were advised to watch for artifacts such as Event ID 4624 with LogonType 9 and to account for detection gaps where Kerberos ticket operations may occur without direct LSASS process access.
APT techniques: Access Token manipulation. Token theft. Simple C++ example. - cocomelonc
Emotet infection with Cobalt Strike - SANS ISC
Attacks on industrial control systems using ShadowPad - Kaspersky ICS CERT EN
Researchers reported a cyber-espionage campaign using the ShadowPad backdoor against industrial control system operators, telecommunications providers, and government-linked organizations in Pakistan, Afghanistan, Malaysia, and later Argentina-linked victimology. In several intrusions, attackers gained initial access through Microsoft Exchange Server exploitation tied to CVE-2021-26855, while another cluster used trojanized MSI installers for Pakistan government eOffice software to deliver a malicious mscoree.dll loader and encrypted payloads under SYSTEM privileges. Kaspersky said the activity began around March 2021 and assessed with high confidence that a Chinese-speaking threat actor was responsible, though it stopped short of a definitive link to HAFNIUM; Trend Micro likewise found overlaps with previously reported China-linked ShadowPad activity but said attribution remained inconclusive. The intrusions relied on multiple execution and persistence methods, including launching ShadowPad through the legitimate AppLaunch.exe, DLL hijacking via OleView with IVIEWERS.dll and IVIEWERS.dll.dat, and web-shell access consistent with tooling such as China Chopper. Post-compromise operations included credential theft, lateral movement, scheduled tasks, Cobalt Strike, PlugX, Mimikatz, procdump, Nextnet scanning, RAR archiving, and data exfiltration over BITS, indicating a sustained effort to harvest sensitive information from strategically important networks.