BadPotato
BadPotato is a Windows local privilege-escalation tool/exploit used to elevate execution to NT AUTHORITY\SYSTEM. The provided content consistently describes it as part of the Potato-family privilege-escalation toolkit, similar to SharpToken, and specifically notes abuse of named-pipe impersonation to obtain SYSTEM-level command execution. It has been observed as a DLL named BadPotato.dll, including an in-memory sample with MD5 B8A468615E0B0072D2F32E44A7C9A62F. BadPotato has been used by multiple threat actors and intrusion clusters, including APT41, which used a ConfuserEx-obfuscated BADPOTATO exploit for local SYSTEM privilege escalation during campaign C0017, and other China-linked activity clusters such as DragonSpark and Unit 42’s CL-STA-0048 and CL-STA-0046. In those cases it was used post-compromise alongside other tooling such as JuicyPotato, SweetPotato, RasmanPotato, and SharpToken after initial access to internet-exposed servers or web applications. The content also notes a CLR SqlShell variant named CLR_module that embeds BadPotato and EfsPotato for use in compromised Microsoft SQL Server environments. High-confidence indicators from the content include the filename BadPotato.dll and MD5 B8A468615E0B0072D2F32E44A7C9A62F.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BadPotato: a tool similar to SharpToken that elevates user privileges to SYSTEM for command execution.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
Privilege Escalation
3 techniques
Privilege Escalation
To gain system privileges, the threat actors used several variants of the well-known Potato tools, either as memory-only modules or as standalone executables... Of all the tools, the GodPotato standalone binary ultimately succeeded in gaining system privileges.
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation tool used to obtain SYSTEM-level execution on Windows.
A Potato-family privilege-escalation module observed loaded in IIS worker process memory during post-exploitation.
A local privilege escalation tool from the Potato Suite used to elevate privileges to SYSTEM for command execution.
Potato-family local privilege escalation tool used in attempted privilege escalation.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.