CyberSecurity SEE

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

Hackers Utilize AI Agents and GodPotato Exploit to Achieve Windows SYSTEM Privileges

In a troubling development reported by cybersecurity researchers, a group of hackers successfully exploited an exposed application endpoint, using advanced AI agents to take full administrative control of a server in less than 24 hours. This sophisticated attack did not rely on new malware or zero-day vulnerabilities but instead involved a series of commands, credential theft, and privilege escalation techniques, particularly within the Windows operating environment.

Austin Ritchie and Daxton Wirth, the researchers at the forefront of this investigation, confidently concluded that a substantial portion of the hacking operation was driven by large language model (LLM) agents. Their findings were bolstered by concrete evidence, including a live orchestration dashboard hosted on the same IP address from which the attackers submitted their malicious jobs. This dashboard, identified as Cairn, is an open-source platform that allows users to coordinate complex tasks performed by AI agents.

The intrusion commenced via an internet-facing job submission feature linked to an Apache Tomcat application utilizing Spring Batch. Alarmingly, this endpoint accepted task definitions without requiring any form of authentication, thus opening an avenue for the attackers to invoke Nashorn, a JavaScript engine embedded within the application’s Java environment.

Upon execution, the malicious code initiated operations within the existing application process under the privileges afforded to it, avoiding the creation of child processes. This clever stratagem limited detection possibilities—particularly in process-based detection contexts—making the hackers’ activities much less visible to cybersecurity defenses.

Rather than employing a typical approach that might involve installing a web shell, the attackers used a method that deliberately triggered exceptions, and exploited returned error messages to gather command results. However, this tactic also imposed significant restrictions, as the output was limited to fixed 1,800-byte chunks. The attackers cleverly utilized sequential job identifiers to track file offsets and upload positions, thereby preserving the execution state across hundreds of individual requests.

These operations allowed the hackers to engage in extensive reconnaissance, credential discovery, and ultimately, exploitation. They discovered plaintext credentials with elevated SQL Server sysadmin rights by reading through application configuration files. Following this, they enabled “xp_cmdshell,” a feature that allowed them to execute operating system commands under the database service account. They also identified an opportunity for further privilege escalation through “SeImpersonatePrivilege.”

To cement their dominance over the compromised system, the hackers deployed two publicly available tools, PrintSpoofer and GodPotato. These utilities exploit impersonation privileges to gain SYSTEM-level access, the highest security privilege in Windows. Both tools were transmitted as base64-encoded fragments and were later reconstructed on the compromised host. Although the initial strategy encountered difficulties due to file-permission errors, the attackers pivoted to a different approach and ultimately achieved SYSTEM access.

Once they secured this coveted level of access, the hackers proceeded to save crucial registry hives—namely SAM, SYSTEM, and SECURITY—which permitted them to extract local password hashes and other credential data offline. They also established local administrator accounts and made attempts to cover their tracks by disabling xp_cmdshell and purging evidence of their intrusion.

One interesting aspect of this attack was the methodical nature of the command submissions, which exhibited a median interval of approximately six seconds. Analyzing these submissions revealed programmatically generated identifiers, structured output, syntax repairs, and timeout adjustments. These characteristics strongly hinted at a feedback-driven adaptation process rather than adhering to a fixed sequence of commands.

Despite these indicators, ReliaQuest, the cybersecurity firm that conducted the research, cautioned that such behaviors alone do not definitively prove LLM involvement. Investigators were unable to ascertain the specific model, the number of agents employed, or the extent of human oversight in the operation.

In light of this incident, experts urge organizations to take immediate protective measures. Key recommendations include authenticating and restricting access to management endpoints, maintaining detailed job histories, and correlating application exceptions with telemetry from databases and endpoints. Organizations are also advised to safeguard credentials within protected secret storage and to limit service account privileges thoroughly. Implementing automated containment measures is particularly important, especially when early malicious executions remain confined within an existing application process.

Overall, this incident highlights the critical need for heightened vigilance in cybersecurity practices and the potential for AI technologies to facilitate both sophisticated attacks and, conversely, enhanced protections.

Source link

Exit mobile version