Threat reportThreat IntelligenceTL-2026-3220
AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch Endpoint to GodPotato/PrintSpoofer SYSTEM Escalation on Windows
AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch (TL-2026-3220) is a high-severity tracked intrusion set, first published 2026-10-10. It has no confirmed attribution, affects Apache Software Foundation Apache Tomcat hosting a Spring Batch, maps to 12 MITRE ATT&CK techniques (T1003.002, T1003.004, T1027.013), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-3220
- Threat ID
- TL-2026-3220
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
Malware and tooling: Cairn, GodPotato, PrintSpoofer, certutil - S0160
How AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch works
ReliaQuest assessed with high confidence that LLM-driven agents performed substantial portions of an intrusion that took an unauthenticated Apache Tomcat Spring Batch job-submission endpoint to full administrative control of a Windows server in under 24 hours. No new malware or zero-day was used; the chain relied on Nashorn JavaScript execution, plaintext configuration credentials, SQL Server xp_cmdshell and the public GodPotato/PrintSpoofer tools. A live Cairn (open-source agent orchestration) dashboard on the attacker's IP was the strongest evidence of AI involvement.
ReliaQuest researchers Austin Ritchie and Daxton Wirth (research published 2026-10-07, covered by GBHackers and CyberPress on 2026-10-10) documented an intrusion in which an internet-facing Apache Tomcat application using Spring Batch exposed a job-submission feature that accepted task definitions without authentication. The attacker submitted jobs that invoked Nashorn, the JavaScript engine available in the application's Java environment, so attacker code ran in-process with the privileges of the application account. Command output was returned through application-level error messages in fixed 1,800-byte chunks, and jobs carried sequential, programmatically generated identifiers that preserved execution state across requests. On the Linux side of the application host, artifacts included /tmp/out_<jobname>.txt output files, a dot-prefixed staging directory /var/tmp/.x/ holding shell scripts, and a scanning/reconnaissance binary at /var/tmp/kvragent.
The operator read plaintext credentials from application configuration files and recovered a SQL Server sysadmin account, then used SQL Server xp_cmdshell to execute commands as the database service account on the Windows server. Public privilege escalation tools PrintSpoofer and GodPotato, both abusing SeImpersonatePrivilege, were delivered as base64 fragments through the command channel, reassembled with certutil (C:\Windows\Temp\ps.b64 -> ps.exe; C:\Windows\Temp\gp.b64 -> C:\Users\Public\g.exe) and used to obtain SYSTEM. The attacker then dumped the SAM, SYSTEM and SECURITY registry hives for offline password-hash recovery and created a local administrator account.
Evidence of LLM involvement: hundreds of commands at a median gap of roughly six seconds, programmatically generated identifiers, structured output, repeated corrections addressing preceding errors (feedback-driven adaptation rather than a predetermined script), and a live Cairn orchestration dashboard displaying agent findings and next-step planning hosted on 204.194.55.189, the same IP that submitted the malicious jobs. Cairn (by Oritera, AGPL-3.0, first released 2026-04-19) is a legitimate open-source blackboard-style state-space search engine validated on autonomous penetration testing, with Claude, Codex and Pi backends. ReliaQuest cautioned that these behaviors alone do not prove LLM involvement and that the number of agents, the underlying model and the degree of human approval could not be determined. No threat actor is attributed, no CVE is assigned, and product versions were not disclosed. The primary ReliaQuest report was not retrievable during this research; facts here derive from two secondary articles, the search-result summary of the ReliaQuest research, and the public Cairn project page.
MITRE ATT&CK techniques used in TL-2026-3220
Credential Access
T1003.002 Security Account Manager; T1003.004 LSA Secrets; T1552.001 Credentials In Files
Defense Evasion
T1027.013 Encrypted/Encoded File; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories
Execution
Privilege Escalation
T1134.001 Token Impersonation/Theft
Persistence
T1136.001 Local Account; T1505.001 SQL Stored Procedures
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Affected products and versions in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
- Apache Software Foundation — Apache Tomcat hosting a Spring Batch application with an exposed job-submission endpoint (misconfiguration, not a product vulnerability)
- Microsoft — Windows Server / SQL Server (abused via SeImpersonatePrivilege and xp_cmdshell; configuration weakness)
Remediation for AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
Immediate actions
- Require authentication and authorization on Spring Batch job-submission and other management endpoints; remove them from internet exposure
- Block and hunt for 204.194.55.189, 204.194.54.240 and 94.177.131.113 in proxy, firewall and web logs
- Hunt for ps.exe/g.exe, ps.b64/gp.b64 in C:\Windows\Temp and C:\Users\Public, and /var/tmp/.x/ and /var/tmp/kvragent on Linux hosts
- Audit for newly created local administrator accounts and rotate credentials stored in application configuration files and SQL Server sysadmin accounts
Workarounds
- Restrict network access to the Tomcat management/job endpoints to trusted administrative networks
- Disable xp_cmdshell and restrict certutil use by service accounts
Longer-term hardening
- Move credentials out of plaintext configuration into protected secrets storage
- Reduce service-account privileges; remove SeImpersonatePrivilege where not required and disable xp_cmdshell
- Retain Spring Batch job histories and correlate application exceptions with system telemetry
- Implement automated containment for malicious in-process code execution (e.g. Nashorn script invocation from web application processes)
Weaknesses (CWE) in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
Timeline of AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
- Oritera releases the open-source Cairn agent orchestration / autonomous penetration-testing platform (AGPL-3.0), later observed on attacker infrastructure
- As reported, base64-fragmented PrintSpoofer and GodPotato are reassembled with certutil and abuse SeImpersonatePrivilege to reach SYSTEM; SAM/SYSTEM/SECURITY hives dumped and a local admin created (date of activity undisclosed; report date used)
- As reported, attacker reads plaintext application config credentials, obtains a SQL Server sysadmin account and runs commands via xp_cmdshell (date of activity undisclosed; report date used)
- As reported, jobs submitted from 204.194.55.189 to the unauthenticated Spring Batch endpoint invoke Nashorn JavaScript for in-process execution; output returned via error messages in 1,800-byte chunks (date of activity undisclosed; report date used)
- ReliaQuest publishes research (Austin Ritchie, Daxton Wirth) on an intrusion where an unauthenticated Tomcat Spring Batch endpoint led to full admin control in under 24 hours; exact intrusion dates are not disclosed
- GBHackers and CyberPress publish coverage of the ReliaQuest findings, including IOCs and the Cairn dashboard evidence
Sources cited for AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch
- Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges
- Hackers Deploy AI Agents to Automate Server Compromise and Privilege Escalation
- ReliaQuest Threat Spotlight blog (publisher of the Ritchie/Wirth research, published 2026-10-07)
- Cairn - AI general-purpose state-space search engine (Oritera)
- Cairn project overview and trend data
- GodPotato (SeImpersonatePrivilege abuse tool)
- PrintSpoofer (SeImpersonatePrivilege abuse tool)
Detection coverage for TL-2026-3220
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3220 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.