Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials
ID: c5fc0f20-df1a-51cb-9d49-12d17c3598ef
STIX ID: report--c5fc0f20-df1a-51cb-9d49-12d17c3598ef
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes Forest Blizzard (STRONTIUM) deploying a custom tool, GooseEgg, to exploit the Windows Print Spooler vulnerability (CVE-2022-38028) to achieve SYSTEM privileges and steal credentials; the report includes technical analysis of the exploitation chain, persistence and launcher behavior, IOCs (file names and SHA-256 hashes), hunting queries, detection guidance, and mitigation recommendations for targeted government, NGO, education, and transportation-sector organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
