BadPotato is a Windows local privilege-escalation tool in the Potato family used to elevate execution to NT AUTHORITY\SYSTEM, commonly by abusing impersonation mechanisms such as named-pipe impersonation on misconfigured or vulnerable hosts. It is typically deployed after initial compromise as a post-exploitation utility rather than as a standalone initial-access payload. Operators use it to obtain SYSTEM-level command execution and to enable follow-on actions such as credential access, memory dumping, account creation, shellcode execution, and broader hands-on-keyboard activity.
BadPotato has been observed embedded in or invoked by SQL Server post-exploitation tooling, including CLR-based SqlShell variants used against exposed or weakly secured Microsoft SQL Server environments. In those intrusions, it serves as an escalation component that expands the attacker’s control from database-level execution to full operating-system privilege. It has also appeared alongside other Potato-family tools such as JuicyPotatoNG, SweetPotato, SigmaPotato, RustPotato, EfsPotato, and RasmanPotato, reflecting interchangeable operator tradecraft for Windows privilege escalation.
Use of BadPotato has been associated with multiple threat clusters and intrusion sets, including activity attributed to APT41 and Chinese-speaking operators, as well as opportunistic compromises of web servers, IIS environments, and MS-SQL servers. It has been observed in campaigns involving web shells, SQL-based command execution, and deployment of additional malware or remote-access tooling. BadPotato is best characterized as a specialized Windows privilege-escalation exploit/tool used during post-compromise operations to obtain SYSTEM privileges and facilitate subsequent attacker objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SqlShell used in these attacks supports not only basic functions such as command execution and payload downloads but also capabilities like privilege escalation using BadPotato and EfsPotato
Threat actors are using various privilege escalation tools, such as JuicyPotatoNG, SigmaPotato, BadPotato, and RustPotato.
BadPotato: a tool similar to SharpToken that elevates user privileges to SYSTEM for command execution.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named offensive tool used for privilege escalation from the implanted SqlShell.
A privilege escalation tool present in the actor's toolkit.
A privilege-escalation tool used by the installed SqlShell to elevate privileges on compromised systems.
A privilege escalation tool used to obtain SYSTEM-level execution on Windows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.