logo

Russia's Fancy Bear Pummels Windows Print Spooler Bug

ID: 0abe0838-29b6-5b7d-9259-f4684f8cce43

STIX ID: report--0abe0838-29b6-5b7d-9259-f4684f8cce43

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-04-23

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

**Executive Summary:** Microsoft Threat Intelligence attributes use of a custom GooseEgg tool to Fancy Bear (APT28), which exploits CVE-2022-38028 in the Windows Print Spooler to obtain SYSTEM privileges, launch embedded DLLs (e.g., files with "wayzgoose"), steal credentials, and enable follow-on actions such as remote code execution and lateral movement against government, NGO, education, and transportation targets across Ukraine, Western Europe, and North America; Microsoft recommends applying the CVE-2022-38028 patch, using Defender detections, and disabling Print Spooler on domain controllers where feasible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.