Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Banner Thumbnail
Attack Overview

Andariel's RID hijacking: When Windows trusted the wrong account

Year of occurrence: 2023 (attacks occurred; publicly reported by AhnLab in January 2025)

The attack RID hijacking to turn a low-privileged account into an administrator

Andariel, a North Korean state-sponsored group under Lazarus, gained SYSTEM privileges on Windows systems using PsExec and JuicyPotato. After obtaining high-level access, the attackers created a low-privileged local account and modified the Security Account Manager (SAM) registry to replace its Relative Identifier (RID). This caused Windows to treat the unprivileged account as a full administrator.

Additional registry edits and account removal steps were used to hide the activity, enabling the attackers to operate with elevated privileges under the guise of a normal user account.

Severity High

RID hijacking is a powerful escalation technique because it abuses a core Windows trust assumption. Once the RID is altered, traditional privilege checks fail to expose the elevated rights.

State-sponsored groups like Andariel increasingly rely on this method because it bypasses common security controls, leaves minimal logs, and provides durable persistence on compromised systems.

How it impacted organizations

RID hijacking allowed attackers to:

Stealthy backdoor

Allowed attackers to create stealthy backdoor accounts that appeared legitimate but functioned as admins.

Alert evasion

Enabled privilege escalation without triggering traditional admin creation alerts.

Blended activity

Allowed attackers to perform administrative tasks while blending into normal user activity.

Lateral movement

Facilitated lateral movement and persistence using what appeared to be a harmless local user.

Forensic difficulty

Made forensic investigations significantly harder due to cleaned registry traces and removed accounts.The modified RID gave attackers silent, long-term administrative control while appearing to use a regular low-privilege user.

With ADAudit Plus in place, organizations can

 
RID Hijacking
  • Use the dedicated RID Hijacking report to track potential privilege escalation attempts.
  • Detect unauthorized modifications to critical binary values named F that are exploited in RID hijacking attacks.
  • Send immediate alerts when patterns indicate hidden privilege escalation, allowing timely response.
  • Monitor the SAM hive path SAM\SAM\Domains\Account\Users where attackers typically manipulate RIDs.
RID Hijacking Overview

Outcome

With ADAudit Plus RID hijacking attempts and any suspicious privilege escalation would have been visible in real time, enabling organizations to respond immediately.

More security stories

More story thumbnail

BadSuccessor: The silent domain takeover hiding in plain sight

Security story: CVE-2025-59287 – When the patch server becomes the attack vector

CVE-2025-59287: When the patch server becomes the attack vector

Security story: Password spraying – How five months of silent credential attacks went undetected

Password spraying: How five months of silence went undetected

Security story: The 2017 S3 breach – How four misconfigured buckets exposed an entire client base

The 2017 S3 breach: When four buckets exposed an entire client base

Schedule a personalized demo with our experts or see ADAudit Plus in action directly from your browser

ADAudit Plus Trusted By