PrintSpoofer is a publicly available Windows local privilege-escalation utility that abuses SeImpersonatePrivilege to impersonate a privileged token and launch a specified process as NT AUTHORITY\SYSTEM. It has been used extensively as a post-compromise tool by multiple threat actors and in ransomware, espionage, and opportunistic intrusion operations. It is typically executed after an attacker has obtained code execution under a service or application-pool account that holds SeImpersonatePrivilege, including on Windows 10 and Windows Server 2016/2019 systems. PrintSpoofer enables operators to elevate access and execute follow-on payloads with SYSTEM-level privileges.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.exe process on an IIS web server.
CVE-2024-26230 is a critical vulnerability found in the Windows Telephony Service (TapiSrv), which can lead to an elevation of privilege on affected systems. The exploit leverages a use-after-free in FreeDialogInstance.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tentatives de bypass AMSI, escalade de privilèges via Token Impersonation (GodPotato, PrintSpoofer).
The IoC list identifies svcload.exe as a modified PrintSpoofer derivative.
공격 과정에서는 일반적인 MS-SQL 서버 대상 공격 사례와 유사하게 권한 상승을 목적으로 PrintSpoofer 악성코드가 함께 사용되었다.
During the investigation of the second campaign, we collected multiple hacking tools used for privilege escalation (PrintNightmare and PrintSpoofer)
“The attackers used this technique to load and execute several tools as payloads, including FRP, PrintSpoofer…”
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“SeImpersonatePrivilege was enabled — a classic path to SYSTEM on Windows... SYSTEM shell.”
Potato-family privilege escalation tools ... use token spoofing techniques, such as PrintSpoofer, to gain SYSTEM privileges.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows token-spoofing privilege-escalation tool/technique used in the incident to obtain SYSTEM-level execution.
Windows privilege-escalation tool used for token impersonation in the intrusion.
Windows privilege-escalation tool used to obtain higher privileges on compromised systems.
Windows privilege-escalation tool observed being downloaded by the attackers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.