Juicy Potato
Juicy Potato is a local privilege escalation tool used to elevate privileges on compromised Windows systems. In the provided reporting, it is described specifically as a privilege escalation tool/local privilege escalation tool used by the China-linked espionage group Flax Typhoon. Microsoft-linked reporting cited here states that Flax Typhoon used Juicy Potato alongside China Chopper, Metasploit, Mimikatz, and SoftEther VPN during stealthy, long-term intrusions focused primarily on Taiwanese organizations, including government, education, critical manufacturing, and IT sectors. The group reportedly gained initial access by exploiting known vulnerabilities in public-facing servers, deployed web shells, and then used tools including Juicy Potato to expand and maintain access, harvest credentials, and support hands-on-keyboard operations. The content does not provide specific Juicy Potato indicators of compromise such as hashes, file paths, mutexes, domains, or IP addresses.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Privilege Escalation
1 techniqueThe group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to exploit privilege escalation vulnerabilities in Windows systems, often used by attackers to gain SYSTEM privileges.
A privilege escalation tool used by Flax Typhoon on compromised systems.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.