Potato Suite is a publicly documented collection of Windows privilege-escalation tools rather than a single malware family. Its components include BadPotato, SweetPotato, and EfsPotato. Attackers use these tools after obtaining access to attempt elevation from limited service-account privileges to SYSTEM-level execution.
Observed users include OP-512 and the China-linked cyberespionage actor Phantom Taurus. In an OP-512 intrusion against an IIS server running Windows Server 2016, the attacker reflectively loaded these three components into the IIS worker process without writing the toolkits to disk and attempted privilege escalation. Phantom Taurus includes Potato Suite in its broader tool inventory alongside China Chopper and Impacket during espionage operations targeting government and telecommunications organizations. These associations establish its use as post-compromise tooling, not as an initial-access mechanism or a standalone espionage implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
“The group uses common Chinese nation-state hacking tools such as the China Chopper web shell, Potato suite and Impacket...”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation privilege escalation toolkit used to elevate access to SYSTEM on compromised Windows hosts.
A collection of Windows exploitation tools that abuse built-in services to elevate limited-service accounts to SYSTEM. OP-512 loaded three named tools from this collection directly into IIS process memory; the observed privilege checks indicated escalation had not yet succeeded.
Collection of Windows privilege-escalation tools referenced as used by Phantom Taurus.
Collection of Windows privilege-escalation tools (commonly leveraging token/impersonation techniques) used post-compromise to elevate privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.