Threat reportThreat IntelligenceTL-2026-3220

AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch Endpoint to GodPotato/PrintSpoofer SYSTEM Escalation on Windows

highACTIVE

AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch (TL-2026-3220) is a high-severity tracked intrusion set, first published 2026-10-10. It has no confirmed attribution, affects Apache Software Foundation Apache Tomcat hosting a Spring Batch, maps to 12 MITRE ATT&CK techniques (T1003.002, T1003.004, T1027.013), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-3220

Threat ID
TL-2026-3220
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
13

Malware and tooling in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

Malware and tooling: Cairn, GodPotato, PrintSpoofer, certutil - S0160

How AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch works

ReliaQuest assessed with high confidence that LLM-driven agents performed substantial portions of an intrusion that took an unauthenticated Apache Tomcat Spring Batch job-submission endpoint to full administrative control of a Windows server in under 24 hours. No new malware or zero-day was used; the chain relied on Nashorn JavaScript execution, plaintext configuration credentials, SQL Server xp_cmdshell and the public GodPotato/PrintSpoofer tools. A live Cairn (open-source agent orchestration) dashboard on the attacker's IP was the strongest evidence of AI involvement.

ReliaQuest researchers Austin Ritchie and Daxton Wirth (research published 2026-10-07, covered by GBHackers and CyberPress on 2026-10-10) documented an intrusion in which an internet-facing Apache Tomcat application using Spring Batch exposed a job-submission feature that accepted task definitions without authentication. The attacker submitted jobs that invoked Nashorn, the JavaScript engine available in the application's Java environment, so attacker code ran in-process with the privileges of the application account. Command output was returned through application-level error messages in fixed 1,800-byte chunks, and jobs carried sequential, programmatically generated identifiers that preserved execution state across requests. On the Linux side of the application host, artifacts included /tmp/out_<jobname>.txt output files, a dot-prefixed staging directory /var/tmp/.x/ holding shell scripts, and a scanning/reconnaissance binary at /var/tmp/kvragent.

The operator read plaintext credentials from application configuration files and recovered a SQL Server sysadmin account, then used SQL Server xp_cmdshell to execute commands as the database service account on the Windows server. Public privilege escalation tools PrintSpoofer and GodPotato, both abusing SeImpersonatePrivilege, were delivered as base64 fragments through the command channel, reassembled with certutil (C:\Windows\Temp\ps.b64 -> ps.exe; C:\Windows\Temp\gp.b64 -> C:\Users\Public\g.exe) and used to obtain SYSTEM. The attacker then dumped the SAM, SYSTEM and SECURITY registry hives for offline password-hash recovery and created a local administrator account.

Evidence of LLM involvement: hundreds of commands at a median gap of roughly six seconds, programmatically generated identifiers, structured output, repeated corrections addressing preceding errors (feedback-driven adaptation rather than a predetermined script), and a live Cairn orchestration dashboard displaying agent findings and next-step planning hosted on 204.194.55.189, the same IP that submitted the malicious jobs. Cairn (by Oritera, AGPL-3.0, first released 2026-04-19) is a legitimate open-source blackboard-style state-space search engine validated on autonomous penetration testing, with Claude, Codex and Pi backends. ReliaQuest cautioned that these behaviors alone do not prove LLM involvement and that the number of agents, the underlying model and the degree of human approval could not be determined. No threat actor is attributed, no CVE is assigned, and product versions were not disclosed. The primary ReliaQuest report was not retrievable during this research; facts here derive from two secondary articles, the search-result summary of the ReliaQuest research, and the public Cairn project page.

MITRE ATT&CK techniques used in TL-2026-3220

Credential Access

T1003.002 Security Account Manager; T1003.004 LSA Secrets; T1552.001 Credentials In Files

Defense Evasion

T1027.013 Encrypted/Encoded File; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories

Execution

T1059.007 JavaScript

Privilege Escalation

T1134.001 Token Impersonation/Theft

Persistence

T1136.001 Local Account; T1505.001 SQL Stored Procedures

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1588.002 Tool

Affected products and versions in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

  • Apache Software Foundation — Apache Tomcat hosting a Spring Batch application with an exposed job-submission endpoint (misconfiguration, not a product vulnerability)
  • Microsoft — Windows Server / SQL Server (abused via SeImpersonatePrivilege and xp_cmdshell; configuration weakness)

Remediation for AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

Immediate actions

  • Require authentication and authorization on Spring Batch job-submission and other management endpoints; remove them from internet exposure
  • Block and hunt for 204.194.55.189, 204.194.54.240 and 94.177.131.113 in proxy, firewall and web logs
  • Hunt for ps.exe/g.exe, ps.b64/gp.b64 in C:\Windows\Temp and C:\Users\Public, and /var/tmp/.x/ and /var/tmp/kvragent on Linux hosts
  • Audit for newly created local administrator accounts and rotate credentials stored in application configuration files and SQL Server sysadmin accounts

Workarounds

  • Restrict network access to the Tomcat management/job endpoints to trusted administrative networks
  • Disable xp_cmdshell and restrict certutil use by service accounts

Longer-term hardening

  • Move credentials out of plaintext configuration into protected secrets storage
  • Reduce service-account privileges; remove SeImpersonatePrivilege where not required and disable xp_cmdshell
  • Retain Spring Batch job histories and correlate application exceptions with system telemetry
  • Implement automated containment for malicious in-process code execution (e.g. Nashorn script invocation from web application processes)

Weaknesses (CWE) in AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

CWE-306

Timeline of AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

  • Oritera releases the open-source Cairn agent orchestration / autonomous penetration-testing platform (AGPL-3.0), later observed on attacker infrastructure
  • As reported, base64-fragmented PrintSpoofer and GodPotato are reassembled with certutil and abuse SeImpersonatePrivilege to reach SYSTEM; SAM/SYSTEM/SECURITY hives dumped and a local admin created (date of activity undisclosed; report date used)
  • As reported, attacker reads plaintext application config credentials, obtains a SQL Server sysadmin account and runs commands via xp_cmdshell (date of activity undisclosed; report date used)
  • As reported, jobs submitted from 204.194.55.189 to the unauthenticated Spring Batch endpoint invoke Nashorn JavaScript for in-process execution; output returned via error messages in 1,800-byte chunks (date of activity undisclosed; report date used)
  • ReliaQuest publishes research (Austin Ritchie, Daxton Wirth) on an intrusion where an unauthenticated Tomcat Spring Batch endpoint led to full admin control in under 24 hours; exact intrusion dates are not disclosed
  • GBHackers and CyberPress publish coverage of the ReliaQuest findings, including IOCs and the Cairn dashboard evidence

Sources cited for AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch

Detection coverage for TL-2026-3220

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3220 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats