BadPotato is a Windows local privilege-escalation tool in the Potato family used to obtain NT AUTHORITY\SYSTEM privileges on compromised hosts. It is commonly deployed during post-compromise operations rather than as an initial access payload, and is used to elevate execution context for follow-on actions such as command execution, credential access, persistence, lateral movement enablement, and deployment of additional malware.
BadPotato has been observed in intrusions targeting internet-exposed Microsoft SQL Server and web server environments, where attackers first gain code execution through vulnerable or weakly secured services and then invoke privilege-escalation tooling locally. Reporting associates its use with named-pipe impersonation and related token abuse techniques to achieve SYSTEM-level execution. It has appeared both as a standalone tool and embedded within broader offensive frameworks and SQL Server CLR-based shells that provide command execution, payload download, memory dumping, user creation, shellcode execution, and privilege escalation modules.
The tool has been used by multiple threat actors and intrusion clusters, including activity attributed to APT41 and Chinese-speaking operators targeting South Asia, East Asia, and Southeast Asia. It has also been observed alongside other Potato-family tools such as JuicyPotatoNG, SweetPotato, EfsPotato, SigmaPotato, RustPotato, and RasmanPotato, as well as with post-exploitation tooling including web shells, PlugX, Cobalt Strike, SparkRAT, GotoHTTP, and SQL shell implants. In these operations, BadPotato functioned as an enabler for deeper compromise after initial footholds on Windows servers, especially IIS and MSSQL systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors are using various privilege escalation tools, such as JuicyPotatoNG, SigmaPotato, BadPotato, and RustPotato.
BadPotato: a tool similar to SharpToken that elevates user privileges to SYSTEM for command execution.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation tool present in the actor's toolkit.
A privilege-escalation tool used by the installed SqlShell to elevate privileges on compromised systems.
A privilege escalation tool used to obtain SYSTEM-level execution on Windows.
A Potato-family privilege-escalation module observed loaded in IIS worker process memory during post-exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.