Microsoft: APT28 hackers exploit Windows flaw reported by NSA
ID: 5ac24fa6-eb24-5671-ab4e-649716580421
STIX ID: report--5ac24fa6-eb24-5671-ab4e-649716580421
Feed Name: Bleeping Computer
Threat Score
Microsoft reports that Russian APT28 (Forest Blizzard) has used a custom post-compromise tool called GooseEgg to exploit the Windows Print Spooler vulnerability CVE-2022-38028 since at least June 2020, enabling SYSTEM-level execution, credential theft, persistence (scheduled tasks and batch scripts), and deployment of embedded DLL launchers to install backdoors and move laterally across government, NGO, education, and transportation networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
