Attackers are increasingly leveraging advanced credential theft techniques to compromise Microsoft-based environments, with a focus on identity-first intrusions and abuse of authentication protocols. Kerberoasting attacks have resurged, exploiting legacy RC4 encryption in Kerberos to crack service account passwords, as seen in the Ascension Health ransomware incident. These attacks are facilitated by weak password policies and the continued use of outdated encryption, allowing threat actors to obtain domain administrator credentials and move laterally within networks. The prevalence of credential-based intrusions is underscored by threat intelligence reports indicating that identity attacks are now the leading entry point for breaches.
Simultaneously, authentication coercion attacks are evolving, enabling adversaries to force Windows systems to authenticate to attacker-controlled infrastructure without user interaction. Techniques such as exploiting rarely monitored RPC interfaces and tools like PetitPotam (CVE-2021-36942) have been observed in real-world incidents, targeting critical assets like Domain Controllers. Additionally, threat actors are abusing OAuth consent, device code flow, and service principal credential manipulation to maintain persistent, stealthy access to cloud and SaaS platforms, often pivoting from on-premises exploits to Microsoft 365 environments. Organizations are advised to implement robust monitoring, enforce strong authentication policies, and phase out legacy protocols to mitigate these threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
AlphaHunt published reporting on activity described as 'Typhoon by Consent: Quiet, Durable, Everywhere,' indicating continued public analysis of the Typhoon threat cluster and its persistence methods.
BlackFog published an analysis stating that Kerberoasting had resurged across 2024–2025 due to legacy RC4 encryption, weak service account passwords, and overlooked high-privilege service accounts in Microsoft Active Directory environments.
Palo Alto Networks Unit 42 published research describing how authentication coercion techniques continue to evolve, indicating ongoing attacker innovation around coercing systems into authenticating to adversary-controlled endpoints.
IBM’s 2025 X-Force Threat Intelligence Index reported that 30% of intrusions in 2024 involved stolen or abused credentials, underscoring the scale of credential-based attack techniques such as Kerberoasting.
In May 2024, attackers in the Ascension Health ransomware incident reportedly exploited RC4-encrypted Kerberos service tickets to compromise privileged accounts, illustrating the real-world impact of Kerberoasting in Active Directory environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourceblackfog.com
Open sourceblog.alphahunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.