logo

Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials

ID: c5fc0f20-df1a-51cb-9d49-12d17c3598ef

STIX ID: report--c5fc0f20-df1a-51cb-9d49-12d17c3598ef

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes Forest Blizzard (STRONTIUM) deploying a custom tool, GooseEgg, to exploit the Windows Print Spooler vulnerability (CVE-2022-38028) to achieve SYSTEM privileges and steal credentials; the report includes technical analysis of the exploitation chain, persistence and launcher behavior, IOCs (file names and SHA-256 hashes), hunting queries, detection guidance, and mitigation recommendations for targeted government, NGO, education, and transportation-sector organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.