Microsoft is warning that Russian hackers APT28 are exploiting a Windows Print Spooler vulnerability to gain increased privileges on systems and steal credentials and data, using a hacking tool called GooseEgg.

Specifically, the group has been exploiting vulnerability CVE-2022-38028 “at least since June 2020 and possibly since April 2019.”
Microsoft fixed the vulnerability, reported by the US (NSA), in the October 2022 Patch Tuesday. However, until now, it had not reported that it was actively used in attacks.
See also: Russian hackers APT28 compromise Ubiquiti EdgeRouters for attacks
Russian hackers APT28, part of Military Unit 26165 of the Main Intelligence Directorate of the Russian General Staff (GRU), are using the hacking tool to exploit the Windows vulnerability and deploy additional malicious payloads. In addition, they can execute various commands with SYSTEM-level privileges.
According to Microsoft, hackers install this tool as a Windows batch script named "execute.bat" or "doit.bat", which launches a GooseEgg executable and gains persistence on the compromised system by adding a scheduled task that launches "servtask.bat", a second batch script written to disk.
Additionally, thanks to GooseEgg, they can install a malicious DLL file (in some cases called “wayzgoose23.dll”) within the PrintSpooler service, with SYSTEM privileges.
This DLL is actually an app launcher, which can execute other payloads with SYSTEM-level permissions. Russian hackers APT28 can deploy backdoors, spread to victims' networks, and execute code remotely on compromised systems.
Microsoft has observed that hackers have used GooseEgg to target government organizations in Ukraine, Western Europe , and North America. They have also targeted the education and transportation industries.
See also: Russian hackers APT28 infect organizations with HeadLace backdoor
“While it is a simple launcher application, GooseEgg can create other applications with elevated privileges, allowing threat to support any subsequent goals such as remote code execution, installing a backdoor, and spreading across compromised networks.“.

Russian hackers APT28
Russian hackers APT28 began their operations in the mid-2000s and have been linked to several high-profile attacks. For example, they are believed to be responsible for the breach of the German federal parliament (Deutscher Bundestag) and the attacks on the Democratic Congressional Campaign Committee (DCCC) and Democratic National Committee (DNC) before the 2016 US elections.
To counter the above attacks, it is necessary to apply the necessary security updates. Russian hackers are exploiting a Windows vulnerability. Therefore, fixing the vulnerability could prevent the attacks.
See also: France: Russian hackers APT28 breached critical networks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Software updates are crucial to cybersecurity. When software companies discover security holes or vulnerabilities in their code, they develop updates to fix these problems. These updates usually include fixes that prevent malicious users from exploiting the vulnerabilities and causing damage to the system. Malicious users and attackers are constantly looking for new ways to exploit software and cause damage. Updates allow users to address these new threats by installing the necessary protective measures.
Therefore, be sure to apply software updates as soon as possible after their release. Any delay in installing them may expose your system to risks.
Source: www.bleepingcomputer.com
