Rubeus

MITRE
Malware Type:
Tool
First seen:
Unknown
Last seen:
Unknown
Details:

[Rubeus](https://attack.mitre.org/software/S1071) is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.(Citation: GitHub Rubeus March 2023)(Citation: FireEye KEGTAP SINGLEMALT October 2020)(Citation: DFIR Ryuk's Return October 2020)(Citation: DFIR Ryuk 2 Hour Speed Run November 2020)

Associated Techniques (5)
ID ATT&CK Tactics
T1482 Domain Trust Discovery -
T1558.001 Golden Ticket -
T1558.002 Silver Ticket -
T1558.003 Kerberoasting -
T1558.004 AS-REP Roasting -
Used by Actors (1)
Metadata
ID: 779
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00