#JuicyPotato

Malware/Tool

2023-07-14 • 윈도우 서버를 공격해 악성코드 배포 서버로 사용하는 Lazarus 공격 그룹

JuicyPotato is a Windows privilege-escalation utility abused during Lazarus intrusions rather than malware uniquely developed by the group. In attacks on IIS and Microsoft SQL Server systems, a Themida-packed copy named usopriv.exe was created by the IIS w3wp.exe process. Operators used it to obtain privileges unavailable to the compromised service account, verified escalation with whoami, and launched a DLL loader through rundll32. That loader searched several paths for a GIF-disguised encrypted data file, decrypted its configuration and PE content, and executed the payload in memory.

Tagged Reports

« Back