April 23, 2024, 9:04 a.m. | Tushar Subhra Dutta

Cyber Security News cybersecuritynews.com

Hackers abuse Windows Print Spooler vulnerabilities because it runs with elevated SYSTEM privileges, allowing privilege escalation.  Also, exploiting it enables remote code execution and credential theft. Microsoft exposed the Russian threat actor Forest Blizzard (aka APT28, Sednit, Sofacy, and Fancy Bear), who has been using a custom tool called GooseEgg to elevate privileges and steal […]


The post Russian Hackers Exploiting Windows Print Spooler Using GooseEgg Tool appeared first on Cyber Security News.

abuse actor apt28 bear blizzard called code code execution credential credential theft cyber security escalation exploiting exposed fancy bear forest forest blizzard gooseegg hackers hacking tools malware microsoft print print spooler privilege privilege escalation privileges remote code remote code execution russian russian hackers sofacy system system privileges theft threat threat actor tool vulnerabilities vulnerability windows windows print spooler

More from cybersecuritynews.com / Cyber Security News

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens