logo

Old Windows print spooler bug is latest target of Russia's Fancy Bear gang

ID: 4747b36e-4c00-52ec-b601-6b5b0d6c86ee

STIX ID: report--4747b36e-4c00-52ec-b601-6b5b0d6c86ee

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-04-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Microsoft warns that the GRU-linked group Forest Blizzard (Fancy Bear) has been using a custom tool called GooseEgg to exploit the CVE-2022-38028 Print Spooler elevation-of-privilege flaw to gain SYSTEM privileges, persist, move laterally, and steal credentials across government, education, and transportation targets in multiple regions; Microsoft provides IOCs, hunting queries, and mitigation advice including applying patches and disabling spooler on domain controllers.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.