Token Duplication Privilege Escalation
Malware duplicating access tokens from higher-privilege processes (e.g., SYSTEM services, lsass.exe) to escalate its own privileges. Enables access to protected credential stores and elevated operations.
Detection / Fingerprint
- Go function names:
main.DuplicateUserTokenFromSessionID,main.getSystemToken,main.impersonateSystem,main.Elevate - Windows API imports:
DuplicateTokenEx,OpenProcessToken,ImpersonateSelf,OpenThreadToken - Process enumeration:
main.findLsassProcess— lsass.exe targeting
Implementation Patterns
The AFK Stealer sibling bd6dead7 implements a full token-duplication chain:
main.isAdmin— checks current elevation statusmain.enablePrivilege— enables specific token privileges (e.g.,SeDebugPrivilege)main.findLsassProcess— locateslsass.exePIDmain.getSystemToken— openslsass.exeand duplicates its tokenmain.impersonateSystem— impersonates the duplicated SYSTEM tokenmain.DuplicateUserTokenFromSessionID— duplicates tokens across sessions for UAC bypassmain.Elevate— top-level routine orchestrating the full chain
Defensive Detection
- EDR: process opening
lsass.exewithPROCESS_QUERY_INFORMATION | PROCESS_DUP_HANDLErights - EDR:
DuplicateTokenExfollowed byCreateProcessWithTokenWorImpersonateLoggedOnUser - Behavioral: GUI-subsystem process performing token duplication (unusual for non-service apps)
Cross-References
- Observed in: afk-stealer
bd6dead7f5a0ec51 - Related: SeDebugPrivilege-escalation — similar privilege escalation technique
- Related: eventvwr-uac-bypass — alternative UAC bypass method