New Exploits Target Windows Accounts and PowerShell Scripts

New Exploits Target Windows Accounts and PowerShell Scripts

First seen 9 Sep 2026, 10:12 UTC Sploitus 51.9

Article Content

Browse articles
ThreatCluster

Two new exploits have emerged targeting Windows systems and PowerShell scripts. The 'Suborner' exploit allows the creation of hidden local accounts on Windows systems without triggering event logs, affecting all Windows NT versions from XP to 11. It enables attackers to impersonate existing accounts by hijacking their RID after successful authentication. The 'psobf' exploit is a tool for obfuscating PowerShell scripts, making them harder to analyze and detect, useful for Red Teaming and pentesting. It supports multiple obfuscation levels, including AES-256 encryption. Both tools are intended for authorized use only, but their capabilities pose significant risks if misused. The 'Suborner' exploit was first demonstrated at Black Hat USA 2022, while 'psobf' is a newer release aimed at enhancing script security.

Key Points: • Suborner allows creation of hidden Windows accounts, bypassing event logs. • psobf obfuscates PowerShell scripts, complicating detection and analysis. • Both tools are intended for authorized use but pose risks if misused.

Ask AI about this cluster

Timeline

2022-08-01
Suborner demonstrated at Black Hat USA
The exploit was showcased, highlighting its ability to create hidden accounts on Windows.
Sploitus
2026-09-09
psobf exploit released
The tool for obfuscating PowerShell scripts was published, supporting multiple obfuscation techniques.
Sploitus