JuicyPotato

First seen
2018-07-01 00:00:00
Malware type
exploit-kit
Last IoC activity
2026-07-16 01:22:56
Profile updated
2026-07-07 13:02:01

Context

As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_PRI_Juicypotato (yara-rule)
  • SEKOIA_Tool_Juicypotato_Exploit_Strings (yara-rule)

Reports & references

  • Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
  • Palo Alto Unit 42 — Operation Diplomatic Specter (report)
  • Cisco Talos — Uat 5918 Targets Critical Infra In Taiwan (report)
  • Trend Micro — Earth Lamia (report)
  • sentinelone.com — Bluesky Ransomware Ad Lateral Movement Evasion And Fast Encryption Puts Threat On The Radar (report)
  • asec.ahnlab.com — 85942 (report)
  • ESET — Iispy Complex Server Side Backdoor Antiforensic Features (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Juicy Potato (report)
  • github.com — Juicy Potato (report)
  • lifars.com — Cryptocurrency Miners Xmrig Based Coinminer By Blue Mockingbird Group (report)

External references