Rubeus is an open-source C# toolkit for Kerberos interaction and abuse in Windows Active Directory environments. It is used legitimately by penetration testers and red teams and is also abused by ransomware operators and espionage actors for credential access and post-exploitation. It is a dual-use security tool rather than a dedicated malware family.
Rubeus supports Kerberoasting, extracting encrypted service-ticket material for offline password cracking, and collecting and submitting Kerberos tickets for pass-the-ticket authentication. Its delegation functionality can retrieve a usable ticket-granting ticket for the current user through the Kerberos GSS-API without requiring local elevation. Ticket submission uses native Windows authentication interfaces rather than directly modifying LSASS memory. Stolen tickets and recovered service-account credentials can enable lateral movement and access to privileged domain resources, particularly when service accounts have excessive permissions.
Documented malicious use includes Wizard Spider, Conti, Akira, BlackSuit, and Earth Krahang activity. Operators have executed Rubeus as a compiled tool, loaded it into PowerShell through custom payloads, and injected it into legitimate Windows processes. It is generally deployed after an initial foothold to attack domain authentication rather than serving as an initial-access payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The reported noPac fallback used CVE-2021-42278 and CVE-2021-42287 to request a ticket-granting ticket through the PaperCut server's domain computer account, impersonate the domain controller, and forge a high-privilege service ticket.
Where LSASS memory dumping failed, agents reportedly fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287, using Rubeus or Certipy to obtain and forge high-privilege Kerberos tickets.
BadSuccessor is a critical attack vector that emerged following the release of Windows Server 2025. Under certain conditions, this server version enables users to leverage delegated Managed Service Accounts (dMSAs) to elevate privileges within Active Directory environments running Windows Server 2025. At the time of writing this article, no patch exists for this issue.
This detection leverages Windows Security Event Logs to identify TGT requests with unusual fields, which may indicate the use of tools like Rubeus following the exploitation of CVE-2021-36942 (PetitPotam).
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.
Operators may opt to perform a kerberoasting attack using something like Rubeus.
The attacker then downloaded a custom payload that allowed them to load Rubeus, a toolkit for Kerberos abuse, into PowerShell, rather than ingress a compiled binary.
Akira creates new local accounts for persistence and relies on Mimikatz, LaZagne, and Rubeus for credential theft.
"Rubeus uses the forged certificate to request a TGT as a Domain Admin."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Shadow Credentials - это атака на механизм хранения учётных данных в Active Directory, которая позволяет добавить в атрибут msDS-KeyCredentialLink объекта (пользователя или компьютера) пару ключей, а затем использовать их для получения билета Kerberos (TGT) от имени этого объекта.
After approximately 5 minutes, the malicious actors executed the Exec IcedID command to execute code by injecting the code into a cmd.exe instance.
Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287. | “Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287.”
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Shadow Credentials - это атака на механизм хранения учётных данных в Active Directory, которая позволяет добавить в атрибут msDS-KeyCredentialLink объекта (пользователя или компьютера) пару ключей, а затем использовать их для получения билета Kerberos (TGT) от имени этого объекта.
After approximately 5 minutes, the malicious actors executed the Exec IcedID command to execute code by injecting the code into a cmd.exe instance.
You can specify if you want to use Kerberos or NTLM authentication. If you choose Kerberos, the tool will create a sacrificial token and use Rubeus to import/ask for the ticket. If NTLM is specified, the tool will use SharpKatz SetThreadToken or LogonUser impersonation.
Access Token Manipulation (ATT&CK technique: T1134) ... this section will explain how attackers can abuse access tokens and target the fundamental trust relationships in Windows domains to compromise entire networks.
The createnetonly action will use the CreateProcessWithLogonW() API to create a new hidden (unless /show is specified) process with a SECURITY_LOGON_TYPE of 9 (NewCredentials), the equivalent of runas /netonly.
Customers leveraging the Palo Alto Networks AutoFocus tool can track initially identified samples and tools under the Fireye_RedTeam_Tools, Rubeus, AndrewSpecial, KeeFarce, SafetyKatz, InveighZero, GadgetToJScript, SeatBelt, RuralBishop, SharpView, and SharpZeroLogon tags.
Workstations store Kerberos tickets in the Local Security Authority Subsystem Service (LSASS) memory after user authentication. Attackers with administrative privileges on compromised systems can extract these tickets using tools like Mimikatz or Rubeus.
мы можем добавить свой ключ и залогиниться... есть протокол (PKINIT), который позволяет логиниться без пароля. Есть хранилище ключей (msDS-KeyCredentialLink). Есть права, которые позволяют в это хранилище писать.
The team used a password hash to request a Kerberos TGT and then a Kerberos service ticket; it also used Rubeus asktgs to request service tickets used for Seamless SSO.
Both the Sapphire and Diamond Ticket attacks decrypt a legitimate TGT and change its PAC, and in order to do that, the adversary needs to have access to the KRBTGT account’s key (the password hash). | Diamond and Sapphire Tickets are forged TGTs created by modifying a legitimate TGT, which gives it additional privileges or a new identity.
Adversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC).
One additional account, which was the only one with preauthentication disabled, was compromised via AS-REP roasting.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive credential-access tool identified as being used in Akira intrusions. The article does not specify particular Rubeus commands or techniques.
Kerberos-focused post-exploitation tool used to request a Domain Admin ticket-granting ticket using an abused certificate.
Used to forge and inject a Golden Ticket for Kerberos authentication, enabling privilege escalation to domain-level administrative access.
Rubeus is referenced as an executable offensive security/post-exploitation tool present on the tester's Kali VM and detected by Windows Defender during AppLocker testing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.