logo

Microsoft Outlook Flaw Exploited by Russia's APT28 to Hack Czech, German Entities

ID: db617ea5-e5f2-5ee6-a558-ebb033f1de2b

STIX ID: report--db617ea5-e5f2-5ee6-a558-ebb033f1de2b

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Czech and German authorities disclosed a long-running GRU‑linked APT28 espionage campaign leveraging an Outlook privilege‑escalation vuln (CVE-2023-23397) and other exploits (including a Print Spooler zero‑day CVE-2022-38028) to access Net-NTLMv2 hashes, relay-authenticate, compromise numerous email accounts, and deliver custom malware (GooseEgg); the actors also used a criminal proxy botnet of compromised routers and pro‑Russia hacktivists have targeted ICS/OT and conducted DDoS operations, prompting multi‑agency warnings and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.