Russia's APT28 Exploited Windows Print Spooler Flaw to Deploy 'GooseEgg' Malware
ID: f2489984-240a-5b64-a3f2-1752037366b1
STIX ID: report--f2489984-240a-5b64-a3f2-1752037366b1
Feed Name: The Hacker News
**Summary:** Microsoft reports that Russia-linked APT28 (aka Forest Blizzard/Fancy Bear) weaponized a Windows Print Spooler privilege-escalation vulnerability (CVE-2022-38028) to deploy a previously undocumented post-compromise tool named GooseEgg—used to spawn elevated processes, deliver DLLs/executables, and enable credential theft and lateral movement across targeted Ukrainian, Western European, and North American government, NGO, education, and transportation networks; the report also highlights IBM X-Force findings on Gamaredon (Hive0051) phishing campaigns delivering multiple GammaLoad malware variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
