JuicyPotato is a Windows local privilege-escalation tool from the Potato family that abuses token impersonation mechanisms, particularly SeImpersonatePrivilege, to elevate execution to NT AUTHORITY\SYSTEM. It is widely used as post-exploitation tooling rather than as a standalone intrusion platform, and commonly appears after initial compromise on exposed servers and application hosts where service accounts or web application pool identities possess impersonation rights but lack full administrative privileges.
The tool has been observed in intrusions targeting Windows IIS web servers, MS-SQL servers, SAP NetWeaver environments, and broader enterprise web infrastructure. Operators deploy it after gaining code execution through vulnerable public-facing applications, web shells, stolen credentials, or other footholds, then use it to execute follow-on payloads and commands with elevated privileges. Reported follow-on activity includes launching loaders and backdoors, enabling broader command execution, facilitating credential theft, and supporting persistence or lateral movement by unlocking higher-privilege access on the compromised host.
JuicyPotato is frequently used by a diverse set of threat actors, including state-linked and criminal operators. Public reporting has associated its use with Lazarus, Blue Mockingbird, Gelsemium-linked activity, UAT-7237, and other Chinese-speaking intrusion clusters, as well as opportunistic attackers compromising internet-exposed infrastructure. In several cases it has been paired with commodity or open-source post-exploitation tooling such as Cobalt Strike, tunneling utilities, web shells, and custom loaders. Some operators also deploy packed or renamed variants to hinder detection.
JuicyPotato should be understood primarily as a privilege-escalation utility for Windows post-compromise operations. Its core role is to convert limited local execution into SYSTEM-level execution, making it a common enabler for subsequent malware deployment, defense evasion, credential access, and deeper compromise of enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware generated by the w3wp.exe process, usopriv.exe is the JuicyPotato malware packed with Themida. The Potato malware strains are responsible for privilege escalation.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers also leverage tools like JuicyPotato for privilege escalation...
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source privilege-escalation tool used by the attackers to elevate privileges during intrusions.
Windows privilege escalation tool used to elevate from low-privileged service contexts (e.g., MS-SQL service) by abusing token/COM-related privileges, enabling subsequent payload execution with higher privileges.
JuicyPotato is a tool that exploits Windows privilege escalation vulnerabilities to gain higher-level access on compromised systems.
JuicyPotato is a tool that exploits Windows privilege escalation vulnerabilities to gain higher-level access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.