Skip to content

Rubeus

Rubeus is an open-source C# toolkit for raw Kerberos interaction and abuse on Windows, particularly in Microsoft Active Directory environments.

Rubeus

Family profile

Rubeus is an open-source C# toolkit for raw Kerberos interaction and abuse on Windows, particularly in Microsoft Active Directory environments. It is a dual-use offensive security tool used by penetration testers and red teams and abused by threat actors for credential access and post-exploitation, rather than a standalone malware implant.

Its capabilities include Kerberoasting, extracting Kerberos tickets, submitting tickets to logon sessions for Pass-the-Ticket authentication, and forging and injecting Golden Tickets when the required KRBTGT key material is available. Kerberoasting obtains service-ticket material for offline password cracking. Its delegation functionality can retrieve a usable ticket-granting ticket for the current user through the Kerberos GSS-API without requiring local elevation. Ticket submission through native Windows authentication interfaces does not require directly opening LSASS, limiting visibility for detections focused on suspicious LSASS process access. These functions support impersonation, privilege escalation, and lateral movement within compromised domains.

Rubeus can execute as a Windows executable or be loaded into memory as a .NET assembly. It has been used in Akira ransomware intrusions and Earth Krahang espionage campaigns. QBot has also deployed Rubeus through injection into a legitimate Windows process; that injection is a deployment technique performed by QBot, not an intrinsic Rubeus capability.

Capabilities

  • Credential Theft
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

7 named in public reporting
Akira

Akira creates new local accounts for persistence and relies on Mimikatz, LaZagne, and Rubeus for credential theft.

UNC-PRNT

"Rubeus uses the forged certificate to request a TGT as a Domain Admin."

WIZARD SPIDER

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

Vanilla Tempest

The threat actor also used the Rubeus C# toolset for raw Kerberos interaction and abuse...

UAT-8837

Rubeus, a C# based toolset for Kerberos interaction and abuse

SVR

“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”

APT29

“To secure long-term access to the environment, the SVR used the Rubeus toolkit to craft Ticket Granting Tickets (TGTs).”

Exploited software

Vulnerabilities linked to Rubeus

4 CVEs

MITRE ATT&CK

Rubeus in ATT&CK

38 distinct techniques

Reporting

Research mentioning Rubeus

Jan 1
Cybereason

THREAT ANALYSIS: Cobalt Strike - IcedID, Emotet and QBot

Threat researchers reported that Emotet, IcedID, and QBot were used as initial access malware to quickly deliver Cobalt Strike on compromised Windows systems, sharply reducing the time defenders had to respond before hands-on-keyboard activity began. In observed intrusions, reconnaissance started within 6 to 8 minutes of infection, while Cobalt Strike was deployed in as little as under an hour to roughly two hours later. The activity was commonly initiated through targeted phishing emails carrying malicious Office documents and macros, with follow-on use of PowerShell, scheduled tasks, Run keys, or services to establish persistence and pull additional payloads.

Oct 28
Cocomelonc Github

APT techniques: Token theft via UpdateProcThreadAttribute. Simple C++ example. - cocomelonc

Security researchers detailed how attackers abuse Windows access tokens to impersonate users, elevate privileges, and move laterally across enterprise environments. The technique relies on the way Windows ties logon sessions, privileges, and cached credentials to access tokens, allowing an attacker with sufficient local rights to duplicate or impersonate another process token and launch a new process under that security context. One proof-of-concept shows a local administrator enabling SeDebugPrivilege, opening a privileged process such as winlogon.exe, duplicating its token, and using CreateProcessWithTokenW to spawn a process as SYSTEM. Additional analysis shows token manipulation extends beyond local privilege escalation into stealthier authentication abuse, including NETONLY logons, Pass-the-Hash, Pass-the-Ticket, and Overpass-the-Hash. Researchers said attackers can abuse Windows APIs such as LogonUserW, CreateProcessWithLogonW, DuplicateTokenEx, SetThreadToken, ImpersonateLoggedOnUser, and LsaCallAuthenticationPackage to create new logon sessions or alter authentication behavior without changing the visible local user context. Defenders were advised to watch for artifacts such as Event ID 4624 with LogonType 9 and to account for detection gaps where Kerberos ticket operations may occur without direct LSASS process access.

Sep 25
Cocomelonc Github

APT techniques: Access Token manipulation. Token theft. Simple C++ example. - cocomelonc

Jul 7
Sans Isc

Emotet infection with Cobalt Strike - SANS ISC

Jun 27
Ics Cert Kaspersky

Attacks on industrial control systems using ShadowPad - Kaspersky ICS CERT EN

Researchers reported a cyber-espionage campaign using the ShadowPad backdoor against industrial control system operators, telecommunications providers, and government-linked organizations in Pakistan, Afghanistan, Malaysia, and later Argentina-linked victimology. In several intrusions, attackers gained initial access through Microsoft Exchange Server exploitation tied to CVE-2021-26855, while another cluster used trojanized MSI installers for Pakistan government eOffice software to deliver a malicious mscoree.dll loader and encrypted payloads under SYSTEM privileges. Kaspersky said the activity began around March 2021 and assessed with high confidence that a Chinese-speaking threat actor was responsible, though it stopped short of a definitive link to HAFNIUM; Trend Micro likewise found overlaps with previously reported China-linked ShadowPad activity but said attribution remained inconclusive. The intrusions relied on multiple execution and persistence methods, including launching ShadowPad through the legitimate AppLaunch.exe, DLL hijacking via OleView with IVIEWERS.dll and IVIEWERS.dll.dat, and web-shell access consistent with tooling such as China Chopper. Post-compromise operations included credential theft, lateral movement, scheduled tasks, Cobalt Strike, PlugX, Mimikatz, procdump, Nextnet scanning, RAR archiving, and data exfiltration over BITS, indicating a sustained effort to harvest sensitive information from strategically important networks.

Mar 28
Cisco

Emotet is Back - Cisco Blogs

Dec 7
Bleeping Computer

Emotet now drops Cobalt Strike, fast forwards ransomware attacks

Apr 20
Elastic Security Labs

How attackers abuse Access Token Manipulation (ATT&CK T1134) | Elastic Blog