#JuicyPotato
Malware/Tool
2023-07-14 • 윈도우 서버를 공격해 악성코드 배포 서버로 사용하는 Lazarus 공격 그룹
JuicyPotato is a Windows privilege-escalation utility abused during Lazarus intrusions rather than malware uniquely developed by the group. In attacks on IIS and Microsoft SQL Server systems, a Themida-packed copy named usopriv.exe was created by the IIS w3wp.exe process. Operators used it to obtain privileges unavailable to the compromised service account, verified escalation with whoami, and launched a DLL loader through rundll32. That loader searched several paths for a GIF-disguised encrypted data file, decrypted its configuration and PE content, and executed the payload in memory.
-
2
Tagged Reports
-
1
Unique Authors
-
11
Active Days