JuicyPotato is a publicly available, open-source Windows local privilege-escalation tool widely abused during post-compromise operations. It exploits Windows token impersonation permissions, notably SeImpersonatePrivilege, to elevate execution from service-account contexts to NT AUTHORITY\SYSTEM. Attackers use it to execute commands and launch additional tools with elevated privileges, particularly after compromising Microsoft IIS web servers or Microsoft SQL Server systems.
JuicyPotato is commonly deployed after initial access and executed through web shells or other attacker-controlled processes. Blue Mockingbird has used it to elevate from IIS application-pool accounts to SYSTEM, and it has also appeared in operations involving Lazarus, Earth Lamia, UAT-7237, UAT-10147, and Manic Menagerie. Its observed use spans web-hosting and IT providers, government environments, and other enterprise servers; it is not specific to a single threat actor or industry.
Attackers distribute precompiled binaries and incorporate the tool into customized execution chains. Observed adaptations include a Themida-packed version used by Lazarus and a VOIDMAW-packaged version used by Earth Lamia for in-memory execution. JuicyPotato's principal role is privilege escalation rather than initial infection, persistence, credential collection, or command-and-control communication.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Table 14 lists “JuicyPotato.exe” under “Privilege escalation” among binaries and scripts from the threat actors’ CNE tooling repository.
We found the actor packaged an entire binary of "JuicyPotato" into the DLL file with "VOIDMAW".
Talos observed the threat actor utilizing multiple “Potato” family tools to achieve system level privileges. While some of these tools, such as GodPotato and JuicyPotato, were downloaded as pre compiled binaries from the internet...
The malware generated by the w3wp.exe process, usopriv.exe is the JuicyPotato malware packed with Themida. The Potato malware strains are responsible for privilege escalation.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Performing privilege escalation using tools such as "GodPotato" and "JuicyPotato"
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
The DLL file ... was named "mscoree.dll," which is one of the libraries loaded by "AppLaunch.exe".
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
SeImpersonatePrivilege (“ Impersonate a client after authentication ”) allows a thread to impersonate any access token through SetThreadToken() , ImpersonateLoggedOnUser() , or CreateProcessWithToken() .
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potato-family local privilege escalation tool used by the actor to gain elevated privileges.
An open-source privilege-escalation tool used by the attackers to elevate privileges during intrusions.
Privilege-escalation tool used by Earth Lamia. A recovered mscoree.dll contains a JuicyPotato binary packaged with VOIDMAW, enabling execution in memory through sideloading by the legitimate AppLaunch.exe executable.
Windows privilege escalation tool used to elevate from low-privileged service contexts (e.g., MS-SQL service) by abusing token/COM-related privileges, enabling subsequent payload execution with higher privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.