BadPotato is a publicly available Windows local privilege-escalation tool in the Potato Suite. It abuses named-pipe impersonation to obtain NT AUTHORITY\SYSTEM privileges and execute commands with elevated permissions. Attackers use it after gaining access to a system, particularly when operating through restricted service accounts on IIS web servers or Microsoft SQL Server installations. It is an exploitation utility rather than a standalone backdoor, ransomware, or cryptocurrency miner.
BadPotato has been deployed through web shells and incorporated into CLR-based SqlShell tooling to support privilege escalation on compromised database servers. Observed deployments include .NET libraries loaded directly into IIS worker-process memory without writing the tool to disk. APT41 has used a ConfuserEx-obfuscated version for SYSTEM-level privilege escalation. Other documented users include DragonSpark, CL-STA-0048, OP-512, and the Larva-26009 and Larva-26010 intrusion clusters. Its use spans espionage and financially motivated intrusions, including attacks against Korean businesses and healthcare infrastructure and organizations in South and Southeast Asia. Cryptocurrency mining, remote access, credential theft, and data collection in these intrusions are performed by accompanying tools rather than by BadPotato itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
Three of these came from the publicly documented “Potato Suite” (“BadPotato,” “SweetPotato,” “EfsPotato”).
The SqlShell used in these attacks supports not only basic functions such as command execution and payload downloads but also capabilities like privilege escalation using BadPotato and EfsPotato
Threat actors are using various privilege escalation tools, such as JuicyPotatoNG, SigmaPotato, BadPotato, and RustPotato.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named offensive tool used for privilege escalation from the implanted SqlShell.
A privilege escalation tool present in the actor's toolkit.
A privilege-escalation tool used by the installed SqlShell to elevate privileges on compromised systems.
A Windows privilege-escalation tool loaded into IIS worker-process memory by OP-512. The comparison table also lists it in CL-STA-0048, GhostRedirector, and DragonRank operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.