ATT&CKSoftwareSkeleton Key

Skeleton Key

S0007

Malware.View on attack.mitre.org

About this malware

Skeleton Key is malware used to inject false credentials into domain controllers with the intent of creating a backdoor password. Functionality similar to Skeleton Key is included as a module in Mimikatz.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1556.001
Domain Controller Authentication

Skeleton Key is used to patch an enterprise domain controller authentication process with a backdoor password. It allows adversaries to bypass the standard authentication system to use a defined password for all accounts authenticating to that domain controller.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Dell Skeleton Open source
    Dell SecureWorks. (2015, January 12). Skeleton Key Malware Analysis. Retrieved April 8, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.