A caller cloned its current token and specified new credentials for outbound connections. The new logon session has the same local identity, but uses different credentials for other network connections.
https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624