# AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch Endpoint to GodPotato/PrintSpoofer SYSTEM Escalation on Windows

> ReliaQuest assessed with high confidence that LLM-driven agents performed substantial portions of an intrusion that took an unauthenticated Apache Tomcat Spring Batch job-submission endpoint to full administrative control of a Windows server in under 24 hours. No new malware or zero-day was used; the chain relied on Nashorn JavaScript execution, plaintext configuration credentials, SQL Server xp_cmdshell and the public GodPotato/PrintSpoofer tools. A live Cairn (open-source agent orchestration) dashboard on the attacker's IP was the strongest evidence of AI involvement.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3220
- **ID:** TL-2026-3220
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ReliaQuest researchers Austin Ritchie and Daxton Wirth (research published 2026-10-07, covered by GBHackers and CyberPress on 2026-10-10) documented an intrusion in which an internet-facing Apache Tomcat application using Spring Batch exposed a job-submission feature that accepted task definitions without authentication. The attacker submitted jobs that invoked Nashorn, the JavaScript engine available in the application's Java environment, so attacker code ran in-process with the privileges of the application account. Command output was returned through application-level error messages in fixed 1,800-byte chunks, and jobs carried sequential, programmatically generated identifiers that preserved execution state across requests. On the Linux side of the application host, artifacts included /tmp/out_<jobname>.txt output files, a dot-prefixed staging directory /var/tmp/.x/ holding shell scripts, and a scanning/reconnaissance binary at /var/tmp/kvragent.

The operator read plaintext credentials from application configuration files and recovered a SQL Server sysadmin account, then used SQL Server xp_cmdshell to execute commands as the database service account on the Windows server. Public privilege escalation tools PrintSpoofer and GodPotato, both abusing SeImpersonatePrivilege, were delivered as base64 fragments through the command channel, reassembled with certutil (C:\Windows\Temp\ps.b64 -> ps.exe; C:\Windows\Temp\gp.b64 -> C:\Users\Public\g.exe) and used to obtain SYSTEM. The attacker then dumped the SAM, SYSTEM and SECURITY registry hives for offline password-hash recovery and created a local administrator account.

Evidence of LLM involvement: hundreds of commands at a median gap of roughly six seconds, programmatically generated identifiers, structured output, repeated corrections addressing preceding errors (feedback-driven adaptation rather than a predetermined script), and a live Cairn orchestration dashboard displaying agent findings and next-step planning hosted on 204.194.55.189, the same IP that submitted the malicious jobs. Cairn (by Oritera, AGPL-3.0, first released 2026-04-19) is a legitimate open-source blackboard-style state-space search engine validated on autonomous penetration testing, with Claude, Codex and Pi backends. ReliaQuest cautioned that these behaviors alone do not prove LLM involvement and that the number of agents, the underlying model and the degree of human approval could not be determined. No threat actor is attributed, no CVE is assigned, and product versions were not disclosed. The primary ReliaQuest report was not retrievable during this research; facts here derive from two secondary articles, the search-result summary of the ReliaQuest research, and the public Cairn project page.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.007 JavaScript
- T1588.002 Tool
- T1552.001 Credentials In Files
- T1505.001 SQL Stored Procedures
- T1134.001 Token Impersonation/Theft
- T1003.002 Security Account Manager
- T1003.004 LSA Secrets
- T1136.001 Local Account
- T1027.013 Encrypted/Encoded File
- T1140 Deobfuscate/Decode Files or Information
- T1564.001 Hidden Files and Directories

## Sources

- [Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges](https://gbhackers.com/hackers-use-ai-agents-and-godpotato-exploit/)
- [Hackers Deploy AI Agents to Automate Server Compromise and Privilege Escalation](https://cyberpress.org/hackers-deploy-ai-agents-to-automate-server/)
- [ReliaQuest Threat Spotlight blog (publisher of the Ritchie/Wirth research, published 2026-10-07)](https://reliaquest.com/blog/)
- [Cairn - AI general-purpose state-space search engine (Oritera)](https://github.com/oritera/Cairn)
- [Cairn project overview and trend data](https://gittrend.io/repo/oritera/Cairn)
- [GodPotato (SeImpersonatePrivilege abuse tool)](https://github.com/BeichenDream/GodPotato)
- [PrintSpoofer (SeImpersonatePrivilege abuse tool)](https://github.com/itm4n/PrintSpoofer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3220
