Old Windows print spooler bug is latest target of Russia's Fancy Bear gang
ID: 4747b36e-4c00-52ec-b601-6b5b0d6c86ee
STIX ID: report--4747b36e-4c00-52ec-b601-6b5b0d6c86ee
Feed Name: The Register (Security)
**Microsoft warns that the GRU-linked group Forest Blizzard (Fancy Bear) has been using a custom tool called GooseEgg to exploit the CVE-2022-38028 Print Spooler elevation-of-privilege flaw to gain SYSTEM privileges, persist, move laterally, and steal credentials across government, education, and transportation targets in multiple regions; Microsoft provides IOCs, hunting queries, and mitigation advice including applying patches and disabling spooler on domain controllers.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
