GodPotato is a publicly available Windows local privilege-escalation tool in the Potato family of token-impersonation utilities. Implemented in C# for the .NET environment, it impersonates a privileged service through named-pipe impersonation to obtain SYSTEM-level access and execute attacker-supplied commands with elevated privileges. It is an offensive security utility rather than a standalone backdoor or ransomware family.
Attackers deploy GodPotato after obtaining an initial foothold, frequently through web shells on compromised IIS, ASP.NET, SharePoint, or SQL Server environments. Observed deployments include standalone compiled executables and custom C# utilities incorporating its exploitation technique. Elevated execution can enable follow-on actions such as creating local administrator accounts, but those actions depend on the commands or surrounding tooling used by the operator.
GodPotato has been used by Earth Lamia, DragonRank, UAT-10147, and the operators of Manic Menagerie 2.0, among other intrusion clusters. Its use spans financially motivated and espionage-related operations against government, healthcare, web-hosting, IT, and payment-related environments. Because it is publicly available and widely reused, its presence alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed the attacker using GodPotato for privilege escalation.
The comparison table lists “BadPotato, GodPotato, PrintNotifyPotato” under DragonRank's privilege-escalation tooling.
The use of the hacking tool "Sophosx64.exe," which is the "GodPotato" tool. We also found the same tool with the same filename used in Earth Lamia's attack.
To escalate privileges, the group used the publicly available GodPotato tool.
GodPotato: Modern token-impersonation LPE tool, staged as C# source and compiled .NET binary.
Tentatives de bypass AMSI, escalade de privilèges via Token Impersonation (GodPotato, PrintSpoofer).
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Performing privilege escalation using tools such as "GodPotato" and "JuicyPotato"
Using tools such as BadPotato, SweetPotato, GodPotato, or PrinterNotifyPotato for privilege escalation on Windows systems
The report identifies privilege escalation through token impersonation, using GodPotato and PrintSpoofer.
The DLL file ... was named "mscoree.dll," which is one of the libraries loaded by "AppLaunch.exe".
Using tools such as BadPotato, SweetPotato, GodPotato, or PrinterNotifyPotato for privilege escalation on Windows systems
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows local-privilege-escalation tool that abuses token impersonation to obtain elevated privileges.
Windows privilege-escalation tool used for token impersonation in the intrusion.
A named Windows privilege-escalation tool used by an Aurora activity cluster as part of a broader ransomware intrusion.
Potato-family local privilege escalation tool used to obtain SYSTEM-level privileges on compromised Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.