Netskope Threat Labs

PrintSpoofer

ATP Sandbox Adv. HeuristicsAV

PrintSpoofer is a public privilege escalation tool that abuses the Print Spooler service to run code with elevated privileges on Windows systems. Red teams and penetration testers use it in authorized testing, and cyberattackers use it to escalate privileges after gaining a foothold.

First seen
June 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.PrintSpoofer
DeepScan:Generic.PrintSpoofer.1.D498B76E
DeepScan:Generic.PrintSpoofer.1.FAD8E734
Generic.PrintSpoofer.1.126A5FD5
Generic.PrintSpoofer.1.1A3D3547
Generic.PrintSpoofer.1.36D0EC94
Generic.PrintSpoofer.1.42EF168D
Generic.PrintSpoofer.1.633C1888
Generic.PrintSpoofer.1.6E09450B
Generic.PrintSpoofer.1.7C02136F