Threat researchers and U.S. government defenders warned that attackers who steal an identity provider's token-signing private key can forge SAML 2.0 assertions and authenticate as arbitrary users to cloud services that trust the compromised provider. The technique, known as Golden SAML, lets intruders bypass normal controls including MFA in some scenarios and obtain access to environments such as AWS, Azure, Microsoft 365, and vSphere. CyberArk showed the method can be used against AD FS federations, including exchanging forged assertions through AWS STS AssumeRoleWithSAML to obtain temporary AWS credentials, while noting the abuse stems from compromised trust infrastructure rather than a flaw in SAML itself.
Mandiant and CISA later tied Golden SAML to broader post-compromise cloud intrusion activity, including operations by UNC2452, and said attackers often pivot from on-premises compromise into cloud tenants by stealing AD FS signing certificates, altering federated domains, abusing privileged Azure AD roles, or adding rogue credentials to applications and service principals. Defenders were urged to treat on-premises and cloud investigations as linked, rotate signing certificates and other secrets, revoke refresh tokens, remove cloud persistence, and harden monitoring around AD FS, federation settings, privileged accounts, and application permissions. Detection remains challenging because forged assertions can closely resemble legitimate federated logins; Splunk noted one analytic for suspicious AWS AssumeRoleWithSAML activity was ultimately removed because it no longer reliably identified the intended abuse.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection "AWS SAML Access by Provider User and Principal" from its library in version 5.4.0, stating it no longer effectively identified the intended malicious activity. The analytic had been aimed at spotting suspicious AssumeRoleWithSAML activity relevant to Golden SAML-style abuse in AWS federated environments.
CISA issued alert AA21-008A on detecting post-compromise threat activity in Microsoft cloud environments. The alert reflects official U.S. government guidance related to techniques such as Golden SAML and other cloud persistence and privilege-abuse methods.
At Black Hat USA 2021, Mandiant presented research on Microsoft 365 intrusions observed in the wild, detailing techniques for stealth, persistence, and large-scale data theft. The presentation disclosed abuse of mailbox audit bypass, license downgrades to disable MailItemsAccessed logging, mailbox folder permissions, and Azure AD application or service principal hijacking for remote tenant access.
FireEye disclosed in December 2020 a widespread campaign it attributed to UNC2452. Later reporting tied some of these intrusions to post-compromise movement from on-premises environments into victims' Microsoft 365 tenants.
In the same disclosure, CyberArk released "shimit," a tool that automates generating and signing forged SAML responses and, in an AWS and AD FS scenario, exchanges them with AWS STS to obtain temporary credentials. The publication also documented operational details and defensive recommendations around AD FS signing-key protection.
CyberArk Labs publicly described an attack it named "Golden SAML," in which attackers with an identity provider's token-signing private key can forge SAML assertions to access trusted cloud services as arbitrary users. The post emphasized this was an abuse of compromised signing keys rather than a flaw in SAML, AWS, or AD FS.
Mandiant reported that in some UNC2452 intrusions, attackers stole AD FS token-signing material and forged SAML tokens to access Microsoft 365 without users' passwords or MFA. The white paper also described additional cloud attack paths including federated-domain modification, abuse of privileged Azure AD roles, and hijacking of Azure AD applications or service principals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcecisa.gov
Open sourcecyberark.com
Open sourcefireeye.com
Open sourcei.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.