logo

Microsoft: APT28 hackers exploit Windows flaw reported by NSA

ID: 1056fb71-ff74-5aac-aa6b-c11be786b51c

STIX ID: report--1056fb71-ff74-5aac-aa6b-c11be786b51c

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft warns that Russian APT28 (aka Forest Blizzard) has been using a custom post-compromise tool named GooseEgg to exploit the Windows Print Spooler vulnerability CVE-2022-38028 (active since at least June 2020) to escalate to SYSTEM, steal credentials and data, and deploy additional payloads across targets in Ukraine, Western Europe, and North America; observed artifacts include batch scripts (execute.bat, doit.bat, servtask.bat) and an embedded launcher DLL (e.g., wayzgoose23.dll) used to persist and execute further malicious components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.