Huntress disclosed "dMSA Ouroboros," a technique that abuses delegated Managed Service Accounts (dMSAs) in fully patched Windows Server 2025 to create self-sustaining persistence and repeatedly extract credentials. The method chains delegated CreateChild and WriteProperty permissions with object ownership, Shadow Credentials stored in msDS-KeyCredentialLink, and self-referential msDS-GroupMSAMembership entries so a rogue dMSA can authenticate and authorize itself to recover the superseded account's NT hash. The researchers said the approach builds on Akamai's BadSuccessor work and differs from Semperis's Golden dMSA research by focusing on post-creation abuse paths.
According to the report, the attack survives password rotation, can persist even after the original attacker account is deleted, and may prevent Domain Admins from fully remediating the compromise unless the malicious dMSA object itself is removed. Huntress said Microsoft's patch for CVE-2025-53779 did not address this abuse path and that Microsoft classified the issue as a persistence mechanism rather than an elevation-of-privilege flaw, declining to issue a further fix. The firm urged defenders to audit delegated CreateChild rights, monitor dMSA creation by non-admin users, and hunt for suspicious msDS-KeyCredentialLink values and self-SID entries in msDS-GroupMSAMembership on dMSA objects.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Huntress published research describing dMSA Ouroboros, a persistence and credential-extraction technique affecting fully patched Windows Server 2025 environments. The technique uses delegated CreateChild and WriteProperty permissions, object ownership, Shadow Credentials, and self-referential GroupMSAMembership entries to repeatedly recover a superseded account's NT hash.
After reviewing the reported issue, Microsoft classified dMSA Ouroboros as a persistence mechanism rather than an elevation-of-privilege vulnerability and declined to provide a servicing update. This left the described abuse path unpatched according to Huntress.
Akamai published follow-up research examining Microsoft's fix for CVE-2025-53779 and the BadSuccessor technique involving delegated Managed Service Accounts in Windows Server 2025. The analysis described how the original attack worked by linking an attacker-controlled dMSA to a target account so the KDC merged the target's privileges and exposed its Kerberos keys, enabling immediate compromise with control of any OU.
Microsoft issued a fix for CVE-2025-53779 in 2025 to address a dMSA-related issue discussed alongside BadSuccessor research. Huntress later stated the patch did not remediate the post-creation abuse path used in dMSA Ouroboros.
Akamai disclosed the BadSuccessor technique in 2025, showing how delegated Managed Service Accounts could be abused in Active Directory. This prior research established the foundation for later investigation into additional dMSA attack paths.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourceakamai.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.