• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Sunday, September 20, 2026
freevirtualsolutions.com
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management
No Result
View All Result
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management
No Result
View All Result
Free Virtual Solutions
No Result
View All Result
Home Enterprise Technology

Microsoft Flags Russian APT28 Exploiting Windows Vulnerability with New Hacking Tool

Ermias S. by Ermias S.
2 years ago
in Enterprise Technology
0
400
SHARES
2.4k
VIEWS
Share on FacebookShare on Twitter



Microsoft has issued a warning regarding the Russian APT28 threat group, revealing that the group is exploiting a vulnerability in Windows Print Spooler to escalate privileges and steal credentials using a newly identified hacking tool dubbed GooseEgg. This tool specifically targets the CVE-2022-38028 vulnerability, which was reported by the U.S. National Security Agency and subsequently patched by Microsoft during its October 2022 Patch Tuesday.

However, Microsoft had not previously flagged this vulnerability as actively exploited.

APT28, which operates under the umbrella of Military Unit 26165 of Russia’s GRU, employs GooseEgg to deploy additional malicious tools and execute commands with SYSTEM-level privileges. The tool is distributed via Windows batch scripts named ‘execute.bat’ or ‘doit.bat,’ initiating a GooseEgg executable that ensures persistence by creating a scheduled task named ‘servtask.bat.’

Moreover, GooseEgg utilizes an embedded malicious DLL, occasionally referred to as ‘wayzgoose23.dll,’ to further manipulate the compromised system. This DLL, functioning as an app launcher within the PrintSpooler service with SYSTEM permissions, facilitates the execution of other payloads, allowing the attackers to install backdoors, navigate laterally across victim networks, and execute remote code.

“Microsoft has observed Forest Blizzard using GooseEgg as part of post-compromise activities against targets including Ukrainian, Western European, and North American government, non-governmental, education, and transportation sector organizations,” stated Microsoft. “While a simple launcher application, GooseEgg is capable of spawning other applications specified at the command line with elevated permissions, allowing threat actors to support any follow-on objectives such as remote code execution, installing a backdoor, and moving laterally through compromised networks.”

APT28, also known as Fancy Bear, has been implicated in numerous high-profile cyberattacks since it first came to prominence in the mid-2000s. Notable past activities include exploiting a zero-day in Cisco routers last year to deploy Jaguar Tooth malware, using compromised Ubiquiti EdgeRouters to avoid detection in recent attacks, and breaches involving the German Federal Parliament and major U.S. political organizations ahead of the 2016 U.S. Presidential Election.



Source_link

Tags: APT28ExploitingFlagsHackingMicrosoftRussianToolVulnerabilityWindows
Previous Post

The Daily Beast’s Hiring a Full-time Lauren Sánchez Reporter

Next Post

How to Become an SEO Lead (10 Tips That Advanced My Career)

Next Post
How to Become an SEO Lead (10 Tips That Advanced My Career)

How to Become an SEO Lead (10 Tips That Advanced My Career)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Customer Support (1,761)
  • Enterprise Technology (4,559)
  • Marketing Support (3,884)
  • Virtual Assistant (4,144)
  • Workforce Management (1,534)

Free Virtual Solutions

Welcome to freevirtualsolutionsThe goal of freevirtualsolutions is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Category

  • Customer Support
  • Enterprise Technology
  • Marketing Support
  • Virtual Assistant
  • Workforce Management

Recent Post

  • Bot And Agent Trust Management Software, Q2 2026
  • Revolut Data Breach Shows How Trusted Government Email Can Become a Hacker’s Master Key
  • Upside/downside
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2023 Freevirtualsolutions.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management

Copyright © 2023 Freevirtualsolutions.com | All Rights Reserved.

Chat with us

Hi there! How can I help you?