typetechniqueconfidencehighcreated2026-08-18updated2026-08-18defense-evasionprivilege-escalationmitre-attckwindowsgo

Token Duplication Privilege Escalation

Malware duplicating access tokens from higher-privilege processes (e.g., SYSTEM services, lsass.exe) to escalate its own privileges. Enables access to protected credential stores and elevated operations.

Detection / Fingerprint

  • Go function names: main.DuplicateUserTokenFromSessionID, main.getSystemToken, main.impersonateSystem, main.Elevate
  • Windows API imports: DuplicateTokenEx, OpenProcessToken, ImpersonateSelf, OpenThreadToken
  • Process enumeration: main.findLsassProcess — lsass.exe targeting

Implementation Patterns

The AFK Stealer sibling bd6dead7 implements a full token-duplication chain:

  1. main.isAdmin — checks current elevation status
  2. main.enablePrivilege — enables specific token privileges (e.g., SeDebugPrivilege)
  3. main.findLsassProcess — locates lsass.exe PID
  4. main.getSystemToken — opens lsass.exe and duplicates its token
  5. main.impersonateSystem — impersonates the duplicated SYSTEM token
  6. main.DuplicateUserTokenFromSessionID — duplicates tokens across sessions for UAC bypass
  7. main.Elevate — top-level routine orchestrating the full chain

Defensive Detection

  • EDR: process opening lsass.exe with PROCESS_QUERY_INFORMATION | PROCESS_DUP_HANDLE rights
  • EDR: DuplicateTokenEx followed by CreateProcessWithTokenW or ImpersonateLoggedOnUser
  • Behavioral: GUI-subsystem process performing token duplication (unusual for non-service apps)

Cross-References

  • Observed in: afk-stealer bd6dead7f5a0ec51
  • Related: SeDebugPrivilege-escalation — similar privilege escalation technique
  • Related: eventvwr-uac-bypass — alternative UAC bypass method