BadPotato is a Windows local privilege-escalation tool/exploit used to elevate execution to NT AUTHORITY\SYSTEM, including via named-pipe impersonation. The content describes it as similar to SharpToken and as part of the broader Potato-family tooling alongside EfsPotato, JuicyPotato, RasmanPotato, SweetPotato, and GodPotato. It has been observed as a standalone tool and as an embedded capability inside other post-exploitation components, including CLR SqlShell/CLR_module on compromised Microsoft SQL Server environments, where it supports privilege escalation after attackers gain access to exposed or weakly secured MS-SQL servers. Reported post-compromise use cases include command execution as SYSTEM and enabling follow-on actions such as memory dumping, user account creation, shellcode execution, lateral movement, and deployment of additional malware.
The content links BadPotato to multiple intrusion sets and campaigns. APT41 used a ConfuserEx-obfuscated BadPotato exploit during campaign C0017 to abuse named-pipe impersonation for local SYSTEM privilege escalation. Unit 42 also reported China-linked cluster CL-STA-0048 using Potato Suite tools including BadPotato to obtain SYSTEM-level execution after compromising an unpatched internet-facing MSSQL server in South Asia. SentinelLABS reported DragonSpark, assessed as operated by a Chinese-speaking threat actor, using BadPotato during opportunistic intrusions against internet-exposed web and MySQL servers in East Asia. Unit 42 additionally observed CL-STA-0046, attributed with moderate confidence to Gelsemium, attempting privilege escalation with Potato Suite tools including BadPotato in a Southeast Asian government environment.
Observed artifacts include a BadPotato DLL identified in memory with original filename BadPotato.dll and MD5 B8A468615E0B0072D2F32E44A7C9A62F. High-confidence context in the content places BadPotato primarily on Windows servers during post-exploitation, especially IIS, SharePoint, web server, MSSQL, and MySQL compromise chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BadPotato: a tool similar to SharpToken that elevates user privileges to SYSTEM for command execution.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
This SqlShell supports command execution, payload download, privilege escalation using BadPotato and EfsPotato
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege-escalation tool used by the installed SqlShell to elevate privileges on compromised systems.
A privilege escalation tool used to obtain SYSTEM-level execution on Windows.
A Potato-family privilege-escalation module observed loaded in IIS worker process memory during post-exploitation.
A local privilege escalation tool from the Potato Suite used to elevate privileges to SYSTEM for command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.