#AndarielHack
North Korean hackers (Andariel) exploit a Windows RID hijacking vulnerability for admin access. They use custom malware and open-source tools for stealthy persistence. Mitigate by monitoring LSA logs, restricting PsExec/JuicyPotato, disabling the Guest account, and using MFA.#AndarielHack
January 24, 2025 at 6:07 PM