Microsoft: APT28 hackers exploit Windows flaw reported by NSA
ID: 1056fb71-ff74-5aac-aa6b-c11be786b51c
STIX ID: report--1056fb71-ff74-5aac-aa6b-c11be786b51c
Feed Name: Bleeping Computer
Microsoft warns that Russian APT28 (aka Forest Blizzard) has been using a custom post-compromise tool named GooseEgg to exploit the Windows Print Spooler vulnerability CVE-2022-38028 (active since at least June 2020) to escalate to SYSTEM, steal credentials and data, and deploy additional payloads across targets in Ukraine, Western Europe, and North America; observed artifacts include batch scripts (execute.bat, doit.bat, servtask.bat) and an embedded launcher DLL (e.g., wayzgoose23.dll) used to persist and execute further malicious components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
