Tag: Russia’s APT28

Microsoft Outlook Flaw Exploited by Russia’s APT28 to Hack Czech, German Entities
News

Microsoft Outlook Flaw Exploited by Russia’s APT28 to Hack Czech, German Entities

The European Union (EU), NATO, the United Kingdom, and the United States denounced Czechia and Germany's disclosure on Friday that they were the subject of a protracted cyber espionage campaign by the nation-state actor known as APT28, which has ties to Russia. A security hole in Microsoft Outlook that was discovered early last year was used to attack certain unidentified businesses in the Czech Republic, according to a statement from the Ministry of Foreign Affairs (MFA) of the Czech Republic. According to the MFA, cyberattacks that target state institutions, political organizations, and vital infrastructure not only endanger national security but also sabotage the democratic processes that underpin our free society read more Microsoft Outlook Flaw Exploited by Russia's APT28 to Ha...
Russia’s APT28 Exploited Windows Print Spooler Flaw to Deploy ‘GooseEgg’ Malware
News

Russia’s APT28 Exploited Windows Print Spooler Flaw to Deploy ‘GooseEgg’ Malware

The nation-state threat actor with ties to Russia, identified as APT28, used a Microsoft Windows Print Spooler component security hole to distribute GooseEgg, a previously unidentified bespoke virus. According to reports, the post-compromise tool was in use as early as April 2019 and may have been in use since June 2020. It took advantage of a vulnerability that has since been fixed that allowed for privilege escalation (CVE-2022-38028, CVSS score: 7.8). Microsoft fixed it in upgrades that were made available in October 2022, and the National Security Agency (NSA) of the United States is credited with first bringing attention to the issue at that time. APT28, also known as Fancy Bear and Forest Blizzard (formerly Strontium), weaponized the bug in attacks against government, non-g...