JuicyPotato is a Windows local privilege-escalation tool from the Potato family that abuses token impersonation, particularly SeImpersonatePrivilege, to execute code as NT AUTHORITY\SYSTEM. It is commonly deployed after initial compromise on Windows servers and is especially prevalent in intrusions involving IIS and MS-SQL environments, where service accounts often possess the privileges needed for exploitation. Operators use it to elevate from low-privileged service contexts such as web application pool accounts to SYSTEM and then launch follow-on payloads or execute arbitrary commands with higher privileges.
The tool is widely used as post-exploitation tradecraft rather than as a standalone access mechanism. Reported use spans multiple intrusion sets and malware operations, including Lazarus activity against IIS infrastructure, Blue Mockingbird intrusions, Gelsemium-linked operations, UAT-7237 and UAT-10147 campaigns, and other Chinese-speaking threat activity. It has also appeared alongside broader toolchains that include web shells, Cobalt Strike, credential theft utilities, tunneling tools, loaders, and custom backdoors.
Observed deployments show JuicyPotato being downloaded as a precompiled binary, installed after successful access to exposed servers, and used to verify elevation before starting secondary malware. In several campaigns it enabled execution of loaders, backdoors, miners, or command sequences under SYSTEM privileges. Its role is therefore best characterized as a privilege-escalation utility that facilitates deeper post-compromise actions, persistence-enabling changes, credential access, and defense evasion by granting attackers a more privileged execution context on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Talos observed the threat actor utilizing multiple “Potato” family tools to achieve system level privileges. While some of these tools, such as GodPotato and JuicyPotato, were downloaded as pre compiled binaries from the internet...
The malware generated by the w3wp.exe process, usopriv.exe is the JuicyPotato malware packed with Themida. The Potato malware strains are responsible for privilege escalation.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
To escalate privileges, the attackers deployed known open-source tools, such as JuicyPotato.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Famille Potato : GodPotato, JuicyPotato (binaires), EfsPotato, RustPotato
If you possess SeImpersonatePrivilege, the path to SYSTEM is guaranteed. You simply upload a tool like PrintSpoofer or JuicyPotato, execute it, and hijack a SYSTEM token.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potato-family local privilege escalation tool used by the actor to gain elevated privileges.
An open-source privilege-escalation tool used by the attackers to elevate privileges during intrusions.
Windows privilege escalation tool used to elevate from low-privileged service contexts (e.g., MS-SQL service) by abusing token/COM-related privileges, enabling subsequent payload execution with higher privileges.
JuicyPotato is a tool that exploits Windows privilege escalation vulnerabilities to gain higher-level access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.