Skip to main content

Boteraser | Website and Server Security Solutions

Tater PrivEsc

Malware

⚠️ Overview

Tater PrivEsc is a post-exploitation privilege escalation tool developed by the open-source community, primarily maintained by Kevin Robertson of Veris Group, and first publicly released in 2016 under the Metasploit auxiliary module "tater". It is categorized as a privilege escalation (PrivEsc) utility, specifically a PowerShell-based exploit that automates the Hot Potato vulnerability (CVE-2016-0099, also known as MS16-075) and related techniques to elevate from a low-privileged user to SYSTEM on Windows systems.

🔧 Technical Capabilities

Tater exploits the Hot Potato technique, which chains HTTP-to-NTLM relay attacks with local NetBIOS name resolution poisoning to obtain a SYSTEM token. It uses the WinRM service (port 5985) or SMB transport to execute commands via a local relay attack, leveraging NTLM authentication to impersonate the SYSTEM account. The tool propagates only as a manually-deployed payload on already compromised hosts; it does not self-propagate. Persistence is not inherent—Tater runs in memory once executed on a target machine. Evasion techniques include running entirely from PowerShell in memory (living-off-the-land), avoiding disk writes, and using encrypted or obfuscated payloads. The tool also supports multiple privilege escalation methods, including the earlier MS16-077 (broadcast relay) and the more recent Juicy Potato variant (CVE-2018-8382) when invoked with appropriate arguments.

📜 History & Notable Incidents

Tater was first documented in a 2016 blog post by Kevin Robertson titled "Hot Potato – Windows Privilege Escalation" (published on the Veris Group blog) and integrated into the Metasploit framework in the same year. It has been observed in multiple red-team exercises and penetration tests, notably in the 2017 DEF CON workshop slides where it was demonstrated as a canonical tool. No high-profile CVE exploitation campaigns have been publicly attributed to Tater itself, but it is frequently used in tandem with initial-access vectors like phishing emails that drop a Tater-enabled payload for lateral movement and escalation. No law enforcement actions have targeted Tater, as it remains a dual-use tool.

🔍 Detection Indicators

Behavioral signatures include execution of PowerShell in a non-interactive mode with command-line arguments referencing "Tater" or "WinRM" relays, spawning of suspicious child processes like "schtasks.exe" or "cmd.exe" under SYSTEM context. Known file hashes are not publicly centralized; however, a typical Tater script MD5 from the Metasploit repository is e8d3c9c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8 (placeholder—actual hash varies). Network indicators include outbound NTLM authentication attempts to the local loopback address (127.0.0.1) combined with SMB or HTTP relay traffic. No unique registry keys or mutexes are created, as the tool runs in memory only.

☠️ Risk & Impact

On compromised systems, Tater enables attackers to achieve full SYSTEM-level access, leading to data exfiltration of local secrets (e.g., SAM hashes, DPAPI keys), installation of persistent backdoors, or lateral movement across a domain. Financial losses from Tater-facilitated attacks are indirect but significant: ransomware groups (e.g., Ryuk, Conti) have been reported using similar Potato-style tools to gain administrative privileges before deploying encryption payloads. The tool primarily affects Windows environments (7/10/Server 2008–2016) with unpatched MS16-075 vulnerabilities. No specific industry sector is disproportionately affected; any physical or virtual Windows host is a target.

🛡️ Mitigation

Apply Microsoft security patches for MS16-075 (KB3134228) and later cumulative updates that close the NTLM relay path, disable unnecessary services like WinRM if not needed, and enforce PowerShell execution policy restrictions (e.g., Constrained Language Mode). Detection rules include Sysmon event ID 1 for suspicious PowerShell parent-child process chains (MITRE ATT&CK technique T1055.001, Process Injection, and T1134.001, Access Token Manipulation).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓