The threat group PowerPool used a publicly disclosed zero-day local privilege escalation flaw in Microsoft Windows ALPC to gain elevated access on compromised systems. The vulnerability affected Windows 7 through Windows 10 and abused the SchRpcSetSecurity API to let restricted users or processes obtain administrator or SYSTEM privileges by overwriting protected files through hard links in C:\Windows\Task. PowerPool reportedly modified and recompiled a public proof-of-concept exploit, then used it to replace GoogleUpdate.exe with a second-stage payload that would later run with elevated privileges.
Initial access was achieved through targeted delivery methods including malicious email attachments and .slk files that launched PowerShell via Microsoft Excel. After escalation, the group deployed a two-stage Windows backdoor and relied on open-source post-exploitation and credential-dumping tools to move laterally inside victim environments. Microsoft later issued a security update through Windows Update to patch the flaw.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A local privilege-escalation vulnerability in Microsoft Windows ALPC, affecting Windows 7 through Windows 10, was publicly disclosed on GitHub along with proof-of-concept exploit code. The flaw involved the SchRpcSetSecurity API and could let a restricted user overwrite protected files via hard links to gain elevated privileges.
Microsoft released a Windows Update patch to fix the ALPC local privilege-escalation vulnerability after it was exploited in the wild. The patch addressed the zero-day abused by the PowerPool campaign.
ESET observed malicious use of the publicly disclosed exploit within two days of disclosure and attributed the activity to a threat group it dubbed PowerPool. The group modified and recompiled the public exploit, then used it to replace GoogleUpdate.exe with second-stage malware to obtain elevated privileges on targeted systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.