Tag: ‘GooseEgg’ Malware

Russia’s APT28 Exploited Windows Print Spooler Flaw to Deploy ‘GooseEgg’ Malware
News

Russia’s APT28 Exploited Windows Print Spooler Flaw to Deploy ‘GooseEgg’ Malware

The nation-state threat actor with ties to Russia, identified as APT28, used a Microsoft Windows Print Spooler component security hole to distribute GooseEgg, a previously unidentified bespoke virus. According to reports, the post-compromise tool was in use as early as April 2019 and may have been in use since June 2020. It took advantage of a vulnerability that has since been fixed that allowed for privilege escalation (CVE-2022-38028, CVSS score: 7.8). Microsoft fixed it in upgrades that were made available in October 2022, and the National Security Agency (NSA) of the United States is credited with first bringing attention to the issue at that time. APT28, also known as Fancy Bear and Forest Blizzard (formerly Strontium), weaponized the bug in attacks against government, non-g...