logo

Microsoft: APT28 hackers exploit Windows flaw reported by NSA

ID: 5ac24fa6-eb24-5671-ab4e-649716580421

STIX ID: report--5ac24fa6-eb24-5671-ab4e-649716580421

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft reports that Russian APT28 (Forest Blizzard) has used a custom post-compromise tool called GooseEgg to exploit the Windows Print Spooler vulnerability CVE-2022-38028 since at least June 2020, enabling SYSTEM-level execution, credential theft, persistence (scheduled tasks and batch scripts), and deployment of embedded DLL launchers to install backdoors and move laterally across government, NGO, education, and transportation networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.