Security researchers detailed how attackers abuse Windows access tokens to impersonate users, elevate privileges, and move laterally across enterprise environments. The technique relies on the way Windows ties logon sessions, privileges, and cached credentials to access tokens, allowing an attacker with sufficient local rights to duplicate or impersonate another process token and launch a new process under that security context. One proof-of-concept shows a local administrator enabling SeDebugPrivilege, opening a privileged process such as winlogon.exe, duplicating its token, and using CreateProcessWithTokenW to spawn a process as SYSTEM.
Additional analysis shows token manipulation extends beyond local privilege escalation into stealthier authentication abuse, including NETONLY logons, Pass-the-Hash, Pass-the-Ticket, and Overpass-the-Hash. Researchers said attackers can abuse Windows APIs such as LogonUserW, CreateProcessWithLogonW, DuplicateTokenEx, SetThreadToken, ImpersonateLoggedOnUser, and LsaCallAuthenticationPackage to create new logon sessions or alter authentication behavior without changing the visible local user context. Defenders were advised to watch for artifacts such as Event ID 4624 with LogonType 9 and to account for detection gaps where Kerberos ticket operations may occur without direct LSASS process access.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A second Cocomelonc tutorial demonstrated an alternative token theft method using UpdateProcThreadAttribute and PROC_THREAD_ATTRIBUTE_PARENT_PROCESS to spawn a child process that inherits the chosen parent process token, such as from winlogon.exe.
A Cocomelonc tutorial published a C++ proof of concept showing how to enable SeDebugPrivilege, open another process token, duplicate it with DuplicateTokenEx, and launch a new process with CreateProcessWithTokenW, using a privileged process such as winlogon.exe to obtain SYSTEM.
Microsoft published documentation for Win32 privilege constants, including privileges relevant to token manipulation scenarios such as SeDebugPrivilege and SeImpersonatePrivilege.
Elastic Security Labs published a technical analysis of how attackers abuse Windows access token manipulation for lateral movement and Active Directory compromise, covering techniques such as NETONLY, Pass-the-Ticket, Pass-the-Hash, and Overpass-the-Hash.
A public GitHub repository published a C++ Windows utility that enables SeDebugPrivilege and SeImpersonatePrivilege, impersonates SYSTEM via winlogon.exe, starts the TrustedInstaller service if needed, and launches a process such as cmd.exe with a duplicated TrustedInstaller token. The visible commit is labeled "Initial Commit."
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourcecocomelonc.github.io
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceelastic.co
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.