GodPotato is a Windows local privilege-escalation tool in the Potato family. It abuses token impersonation through named-pipe and RPC/DCOM-related mechanisms to impersonate a privileged service token and obtain NT AUTHORITY\SYSTEM-level execution from a lower-privileged context. It is commonly distributed as C# source or a compiled .NET executable and is used after initial compromise as a post-exploitation utility. GodPotato has been observed alongside both publicly available and custom intrusion tooling in compromises of Windows servers, including IIS and SQL Server environments, where operators used it to gain SYSTEM privileges before conducting credential access, reconnaissance, persistence, or lateral movement. It has been used by diverse threat actors, including ransomware operators and suspected China-nexus intrusion clusters; its presence alone is not sufficient for attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GodPotato: Modern token-impersonation LPE tool, staged as C# source and compiled .NET binary.
Tentatives de bypass AMSI, escalade de privilèges via Token Impersonation (GodPotato, PrintSpoofer).
Talos observed the threat actor utilizing multiple “Potato” family tools to achieve system level privileges. While some of these tools, such as GodPotato and JuicyPotato, were downloaded as pre compiled binaries from the internet...
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The Domain-Escalation Toolkit: GodPotato... PwnKit (CVE-2021-4034), an nf_tables kernel exploit (CVE-2024-1086), and a Tomcat Ghostcat AJP client.
Using tools such as BadPotato, SweetPotato, GodPotato, or PrinterNotifyPotato for privilege escalation on Windows systems
The report identifies privilege escalation through token impersonation, using GodPotato and PrintSpoofer.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows local-privilege-escalation tool that abuses token impersonation to obtain elevated privileges.
Windows privilege-escalation tool used for token impersonation in the intrusion.
A named Windows privilege-escalation tool used by an Aurora activity cluster as part of a broader ransomware intrusion.
Potato-family local privilege escalation tool used to obtain SYSTEM-level privileges on compromised Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.