PrintSpoofer is a publicly available Windows privilege-escalation tool that abuses SeImpersonatePrivilege to obtain NT AUTHORITY\SYSTEM on supported systems, notably Windows 10 and Windows Server 2016/2019. It is commonly used after an initial foothold or code execution has already been achieved, allowing operators running as service accounts or other privileged-but-not-SYSTEM contexts to impersonate a higher-privilege token and spawn processes with SYSTEM rights.
The tool is frequently observed as a post-exploitation utility in intrusion chains rather than as a standalone initial-access payload. Reported use cases include escalation from compromised IIS application pool or service contexts, MS-SQL server compromises, and follow-on escalation from other local execution contexts such as Network Service. Threat actors and intrusion sets have used PrintSpoofer alongside loaders, downloaders, web shells, remote-access tools, and tunneling utilities to enable subsequent actions including persistence establishment, credential theft, lateral movement, and defense evasion.
Observed campaigns have linked PrintSpoofer use to multiple threat clusters and operators, including Andariel/Lazarus-associated activity, CL-UNK-1068 intrusions, and Earth Longzhi/APT41-related operations. It has also appeared in commodity or mixed-tool attack chains where loaders decrypt or launch it in memory, including process-ghosting-based execution. In these scenarios, successful elevation is often followed by execution of additional payloads, creation of administrator accounts, enabling of remote access, or deployment of persistent tooling.
PrintSpoofer targets Windows environments and is best characterized as a privilege-escalation utility used during post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-26230 is a critical vulnerability found in the Windows Telephony Service (TapiSrv), which can lead to an elevation of privilege on affected systems. The exploit leverages a use-after-free in FreeDialogInstance.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
공격 과정에서는 일반적인 MS-SQL 서버 대상 공격 사례와 유사하게 권한 상승을 목적으로 PrintSpoofer 악성코드가 함께 사용되었다.
During the investigation of the second campaign, we collected multiple hacking tools used for privilege escalation (PrintNightmare and PrintSpoofer)
“The attackers used this technique to load and execute several tools as payloads, including FRP, PrintSpoofer…”
7 distinct techniques documented for this family, organized by ATT&CK tactic.
공격 과정에서는 일반적인 MS-SQL 서버 대상 공격 사례와 유사하게 권한 상승을 목적으로 PrintSpoofer 악성코드가 함께 사용되었다.
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows privilege escalation tool commonly used post-compromise to obtain elevated privileges.
Open-source Windows local privilege escalation tool abused to elevate privileges (also used alongside a custom .NET variant, PrintProgram).
Local privilege escalation tool that abuses SeImpersonatePrivilege (via named pipe/token impersonation) to spawn a process as SYSTEM on Windows (commonly used on Server 2016).
A Windows privilege escalation exploit/tool used to abuse SeImpersonate privilege to elevate from Network Service to SYSTEM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.