SweetPotato is a publicly available Windows local privilege-escalation tool in the Potato family, used during post-exploitation to obtain NT AUTHORITY\SYSTEM privileges from restricted service accounts. Potato-family techniques abuse token impersonation and service-account privileges such as SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege to execute commands or processes with elevated permissions. SweetPotato has been used after attackers gained access to IIS-hosted applications through web shells or server exploitation; it is not itself an initial-access mechanism.
SweetPotato has appeared as standalone tooling, an in-memory .NET DLL, a modified variant adapted for web-shell environments, and a privilege-escalation command within Ladon. Attackers have reflectively loaded it into IIS worker processes without writing the toolkit to disk. Observed deployments include intrusions against South Korean businesses and Southeast Asian government infrastructure, as well as activity tracked as OP-512. It is commonly deployed alongside other Potato-family tools, including BadPotato, JuicyPotato, and EfsPotato. Its use across multiple intrusion clusters does not uniquely identify a threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.exe process on an IIS web server.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor conducted ... privilege escalation through customised tools like JuicyPotato, RottenPotato, and SweetPotato.
Using tools such as BadPotato, SweetPotato, GodPotato, or PrinterNotifyPotato for privilege escalation on Windows systems
Potato-family privilege escalation tools ... use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges.
Using tools such as BadPotato, SweetPotato, GodPotato, or PrinterNotifyPotato for privilege escalation on Windows systems
Potato-family privilege escalation tools ... use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modified Potato-family token-spoofing privilege-escalation tool used to obtain SYSTEM privileges and launch elevated processes such as cmd.exe.
A Windows privilege-escalation tool loaded directly into the IIS worker process by OP-512, without being written to disk, in an attempt to obtain SYSTEM privileges.
SweetPotato is a privilege escalation exploit used to gain SYSTEM-level access on Windows systems, often leveraged in post-exploitation phases.
A Potato-family privilege-escalation module observed in memory and used by the attackers in an attempt to elevate privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.