Tool
GodPotato
- First Reported
- May 5, 2026
- Latest Reported
- Aug 4, 2026
Reported Context (2)
- Several privilege-escalation scripts were observed. gp_reflect.ps1 loads a GodPotato payload in memory and changes LocalAccountTokenFilterPolicy. fix_uac.bat disables UAC and changes the same policy. ms16032.ps1 The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2
- gp_v6_exec.py runs GodPotato, a Windows privilege escalation tool that abuses the Investigation Details Intrusion Targeting 12 Omani Government Entities, With 26,000 Records Extracted
CVE (5)
Malware (2)
Threat Actors (6)
MITRE ATT&CK (32)
Vendors (5)
Products (13)
Tools (9)
Industries (1)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.