Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Skeleton Key

Skeleton Key

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Skeleton Key targets domain controllers by injecting counterfeit passwords that grant persistent backdoor credentials. Its behavior mirrors Mimikatz modules, exploiting process injection to tamper with authentication state. Affected organizations face elevated risk of stealthy lateral movement and long‑term compromise via these forged accounts.

Enhanced Description

Skeleton Key is a Windows‑focused malware construct designed specifically for compromising domain controllers by injecting fabricated credentials that act as backdoor passwords. By forging legitimate account entries within the Active Directory database, it creates covert access paths that an adversary can later exploit to move laterally throughout the network or maintain long‑term persistence. The technique mirrors functionality found in a module of the well‑known credential‑harvesting toolkit Mimikatz – particularly its ability to manipulate the LSASS process and alter authentication state. Skeleton Key leverages similar process injection and memory manipulation tactics, but it is focused on altering domain controller objects rather than merely retrieving secrets. Once injected, these false credentials enable an attacker to authenticate as a privileged user with minimal detection risk, permitting continuous access regardless of legitimate user activity or password rotation. The malware’s design underscores the importance of monitoring Active Directory changes and securing LSASS from unauthorized manipulation.

Key Capabilities

  • Injects fabricated credentials into Active Directory
  • Creates privileged backdoor account entries
  • Leverages LSASS memory manipulation via process injection
  • Enables covert persistence on domain controllers
  • Facilitates lateral movement across the network

ATT&CK Techniques

T1055
T1098
T1078

Recommended Actions

  • Monitor Windows Security Event Log for Account Management events (e.g., 4742, 4720) and flag anomalous account creation from unexpected sources
  • Enable and enforce privileged endpoint protection with real‑time file integrity monitoring of AD DS components
  • Apply least‑privilege principles and regularly rotate domain controller credentials
  • Deploy behavior analytics to detect unauthorized LSASS process injection activities

Suggested Tags

malware
credential-injection
backdoor-password
domain-controller-attack
windows
mimipoket-like

Confidence Assessment

The analysis is based on a brief description citing Dell Skeleton research and known Mimikatz similarities. Detailed technical specifications, code samples, or observed deployment variants are lacking, limiting confidence in specific implementation details and broader prevalence.

Description

Skeleton Key is malware used to inject false credentials into domain controllers with the intent of creating a backdoor password. (Citation: Dell Skeleton) Functionality similar to Skeleton Key is included as a module in Mimikatz.

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.