Skip to content
Threat Feed

Product

Windows Server

5 briefs RSS
high advisory

AI-Coded Malware Used for Active Directory Enumeration and Exfiltration

A threat actor was observed in early June 2026 using AI-generated PowerShell scripts for Active Directory enumeration and then deploying s5cmd for data exfiltration after gaining initial access via RDP, indicating a shift towards AI-augmented tradecraft for rapid and aggressive campaigns.

Windows Server +1 ai-generated-malware active-directory enumeration powershell data-exfiltration windows ransomware-precursor
3r 8t 7i
high advisory

Suspicious Domain Managed Service Account Creation by Unusual User

Detection of a Domain Managed Service Account (DMSA) creation event by a user that typically does not perform this administrative task, potentially indicating privilege escalation or account compromise.

Windows Server +1 privilege-escalation active-directory dmsa
2r 1t
medium advisory

Creation of New DMSA Service Account Potentially Exploiting BadSuccessor Vulnerability

The creation of a new Delegated Managed Service Account (DMSA) within specific Organizational Units (OUs) using the New-ADServiceAccount cmdlet is indicative of potential BadSuccessor privilege escalation attempts in Windows Server 2025 Active Directory environments.

Windows Server +1 privilege-escalation active-directory bad-successor dmsa
2r 2t
low advisory

NLTEST.EXE Used for Domain Trust Discovery

Adversaries may use `nltest.exe` to enumerate domain trusts, gaining insight into trust relationships and the state of Domain Controller replication within a Windows NT Domain, potentially leading to lateral movement.

Windows Server +1 discovery windows nltest domain-trust
2r 2t
high advisory

Abuse of dnscmd.exe to Modify DNS ServerLevelPluginDLL

Attackers can use dnscmd.exe with administrative privileges to configure the Microsoft DNS ServerLevelPluginDll setting, allowing them to load arbitrary DLLs and execute code within the DNS service context for persistence and privilege escalation.

Splunk Enterprise +3 persistence privilege-escalation windows
2r 1t