PrintSpoofer is a publicly available Windows local privilege-escalation utility that abuses SeImpersonatePrivilege through token impersonation to launch processes with NT AUTHORITY\SYSTEM privileges. It is used during post-exploitation to elevate execution from compromised service accounts, including accounts associated with IIS and Microsoft SQL Server. Its use is documented on Windows 10 and Windows Server 2016 and 2019. Successful elevation depends on the executing account possessing the required impersonation privilege; accounts lacking it cannot use this escalation path.
PrintSpoofer has been used by multiple unrelated threat actors, including Andariel, Red Menshen, Earth Longzhi, CL-UNK-1068, the operators of Manic Menagerie 2.0, and Feral Wolf. These operations span espionage, cryptocurrency-mining intrusions, and ransomware campaigns. Operators have used it to run account-creation utilities and other payloads with elevated privileges. Modified derivatives have also been used to deploy and execute loaders as SYSTEM. CherryLoader has delivered PrintSpoofer as an encrypted privilege-escalation payload, while other attack chains have executed it in memory through DLL-based loaders. PrintSpoofer is an exploitation utility rather than a dedicated backdoor, credential stealer, or ransomware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.exe process on an IIS web server.
CVE-2024-26230 is a critical vulnerability found in the Windows Telephony Service (TapiSrv), which can lead to an elevation of privilege on affected systems. The exploit leverages a use-after-free in FreeDialogInstance.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tentatives de bypass AMSI, escalade de privilèges via Token Impersonation (GodPotato, PrintSpoofer).
The IoC list identifies svcload.exe as a modified PrintSpoofer derivative.
공격 과정에서는 일반적인 MS-SQL 서버 대상 공격 사례와 유사하게 권한 상승을 목적으로 PrintSpoofer 악성코드가 함께 사용되었다.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“SeImpersonatePrivilege was enabled — a classic path to SYSTEM on Windows... SYSTEM shell.”
Potato-family privilege escalation tools ... use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows token-spoofing privilege-escalation tool/technique used in the incident to obtain SYSTEM-level execution.
Windows privilege-escalation tool used for token impersonation in the intrusion.
Windows privilege-escalation tool used to obtain higher privileges on compromised systems.
Windows privilege-escalation tool observed being downloaded by the attackers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.