BypassBoss is a custom Windows privilege-escalation tool used by the China-nexus intrusion set Earth Lamia. It is a modified version of Sharp4PrinterNotifyPotato, whose original source code was publicly shared on a Chinese forum. Earth Lamia has deployed BypassBoss in multiple incidents to elevate privileges on compromised systems. The tool's name was identified in its embedded debugging metadata.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We identified a privilege escalation tool that was named "BypassBoss" in the PDB string.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Customized privilege-escalation tool repeatedly used by Earth Lamia. Analysis identifies it as a modified version of Sharp4PrinterNotifyPotato. The actor removes or obfuscates static strings in customized tools to reduce detection.
BypassBoss is a custom privilege escalation tool, based on Sharp4PrinterNotifyPotato, developed and used by Earth Lamia to escalate privileges within compromised environments.
BypassBoss is a customized privilege escalation tool used by Earth Lamia, based on the open-source Sharp4PrinterNotifyPotato. It is designed to escalate privileges on compromised systems, with modifications to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.