Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges
Attackers used AI agents and GodPotato to turn an exposed Tomcat endpoint into Windows SYSTEM access.
ReliaQuest reported an intrusion in which LLM-driven agents, coordinated via a Cairn dashboard, abused an unauthenticated Apache Tomcat Spring Batch job endpoint. Attackers ran Nashorn JavaScript in the application process, pulled results through exceptions in 1,800-byte chunks, and read plaintext SQL Server sysadmin credentials from configuration files. They enabled xp_cmdshell, then staged PrintSpoofer and GodPotato to abuse SeImpersonatePrivilege and gain SYSTEM. They dumped the SAM, SYSTEM, and SECURITY hives, created local administrator accounts, and tried to clean up; no new malware or zero-day was used.
- Unauthenticated Tomcat Spring Batch jobs ran Nashorn JavaScript inside the app process.
- Config files exposed plaintext SQL sysadmin credentials used to enable xp_cmdshell.
- PrintSpoofer and GodPotato abused SeImpersonatePrivilege to obtain SYSTEM.
- Attackers saved SAM, SYSTEM, and SECURITY hives and created local admins.
- Commands arrived about every six seconds; the model was not identified.
Full article656 words · extracted from gbhackers.com · click to collapse
Hackers used AI agents to turn an exposed application endpoint into full administrative control of a server in under 24 hours. The intrusion involved hundreds of commands, credential theft, and Windows privilege escalation without new malware or a zero-day vulnerability.
Researchers Austin Ritchie and Daxton Wirth assessed with high confidence that large language model-driven agents performed substantial portions of the operation.
Their strongest evidence was a live Cairn orchestration dashboard hosted on the same IP address that submitted malicious application jobs.
Hackers Use AI Agents and GodPotato Exploit
Cairn is a legitimate open-source platform for coordinating multistep AI-agent tasks. The attack began through an internet-facing job-submission feature in an Apache Tomcat application using Spring Batch.
The endpoint accepted task definitions without authentication, allowing attackers to invoke Nashorn, a JavaScript engine available within the application’s Java environment.
Malicious code initially executed inside the existing application process with its account privileges, creating no child processes and limiting visibility for process-based detection.

Rather than installing a web shell, attackers deliberately triggered exceptions and retrieved command results through returned error messages.
Restricted output capacity forced information retrieval in fixed 1,800-byte chunks. Sequential job identifiers tracked file offsets and upload positions, preserving execution state across hundreds of requests.
This application-level command channel supported reconnaissance, credential discovery, and subsequent exploitation. Reading application configuration files exposed plaintext credentials with SQL Server sysadmin rights.
Attackers enabled xp_cmdshell to run operating-system commands under the database service account, then identified SeImpersonatePrivilege as an available escalation opportunity.
They staged PrintSpoofer and GodPotato, publicly available utilities that abuse impersonation privileges to obtain SYSTEM, Windows’ highest-privilege local security account.
Both tools arrived as base64-encoded fragments and were reconstructed on the compromised host. After repeated file-permission failures disrupted the first approach, attackers switched tools and achieved SYSTEM access.
The attackers then saved the SAM, SYSTEM, and SECURITY registry hives, enabling offline extraction of local password hashes and other stored credential material. They also created local administrator accounts before attempting cleanup and disabling xp_cmdshell.
Command submissions showed a median interval of approximately six seconds. Programmatically generated identifiers, structured output, syntax repairs, and timeout adjustments indicated feedback-driven adaptation rather than a fixed command sequence.
However, ReliaQuest cautioned that these behaviors alone do not prove LLM involvement. Investigators could not establish the model, agent count, or extent of human approval.
Defenders should authenticate and restrict management endpoints, retain job histories, and correlate application exceptions with database and endpoint telemetry.
Move credentials into protected secrets storage, and reduce service-account privileges. Automated containment is particularly important when early malicious execution remains inside an existing application process.
IOCs
| Indicators & Observables | Context |
| 204.194.55[.]189 | Source of requests that created malicious application jobs; also exposed a Cairn interface and exploit-staging material |
| 204.194.54[.]240 | Sent traffic to the environment prior to the incident; exposed AI-related services and an open directory containing tool-named files matching the incident |
| 94.177.131[.]113 | Retrieved job output and sent POST requests to the upload endpoint; a relay role is possible but unconfirmed |
| /tmp/out_<jobname>.txt | Command output written to a file named after the submitting job |
| /var/tmp/.x/ | Dot-prefixed directory holding shell scripts and a private runtime |
| /var/tmp/kvragent | Binary dropped on the server and used for scanning |
| C:\Windows\Temp\ps.b64 → C:\Windows\Temp\ps.exe | PrintSpoofer: uploaded as base64 fragments through the command channel and reassembled with certutil |
| C:\Windows\Temp\gp.b64 → C:\Users\Public\g.exe | GodPotato: uploaded as base64 fragments through the command channel and reassembled with certutil |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.