CVE-2022-38028
published 2022-10-11CVE-2022-38028: Windows Print Spooler Elevation of Privilege Vulnerability
PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-05-14
Exploited in the wild
EPSS
14.95%
96.3th percentile
Windows Print Spooler Elevation of Privilege Vulnerability
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19507 | 10.0.10240.19507 |
| microsoft | windows_10_1607 | < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_10_1809 | < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_20h2 | < 10.0.19042.2130 | 10.0.19042.2130 |
| microsoft | windows_10_21h1 | < 10.0.19043.2130 | 10.0.19043.2130 |
| microsoft | windows_10_21h2 | < 10.0.19044.2130 | 10.0.19044.2130 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19507 | 10.0.10240.19507 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3532 | 10.0.17763.3532 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2130 | 10.0.19042.2130 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2130 | 10.0.19043.2130 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2130 | 10.0.19044.2130 |
| microsoft | windows_11_22h2 | < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1098 | 10.0.22000.1098 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_8.1 | < 6.3.9600.20625 | 6.3.9600.20625 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20625 | 6.3.9600.20625 |
| microsoft | windows_rt_8.1 | < 6.3.9600.20625 | 6.3.9600.20625 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23920 | 6.2.9200.23920 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20625 | 6.3.9600.20625 |
| microsoft | windows_server_2016 | < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5427 | 10.0.14393.5427 |
| microsoft | windows_server_2019 | < 10.0.17763.3532 | 10.0.17763.3532 |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on files written to and executed from the root of C:\ProgramData — this is the custom detection signature that first identified the APT28 compromise. ↗
- →Detect registry hive dumping (SAM, SECURITY, SYSTEM) via reg save commands writing to C:\ProgramData, followed by PowerShell Compress-Archive — indicative of GooseEgg/APT28 credential harvesting activity. ↗
- ·CVE-2022-38028 was patched by Microsoft in October 2022, but APT28 may have been exploiting it as a zero-day as far back as 2020 — patch status alone does not confirm absence of prior compromise. ↗
- ·GooseEgg can load other applications with SYSTEM-level permissions, enabling remote code execution and deployment of additional backdoors — treat any GooseEgg detection as a full system compromise requiring broad scope investigation. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulnCheck
Microsoft Office Outlook Privilege Escalation Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-23397 [CRITICAL] CWE-294 Microsoft Office Outlook Privilege Escalation Vulnerability
Microsoft Office Outlook Privilege Escalation Vulnerability
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Mar; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.deepinstinct.com/blog/cve-2023-23397-exploitations-in-the-wild-what-you-need-to-
GHSA
GHSA-5vrq-5cmx-xwfc: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-10-12
CVE-2022-38028 [HIGH] GHSA-5vrq-5cmx-xwfc: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-38028 [HIGH] Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.logpoint.com/wp-content/uploads/2024/06/logpoint-etpr-forest-blizzard.pdf; https://www.cyfirma.com/res
VulnCheck
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-34527 [HIGH] CWE-269 Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2021-Jul; https://www.fortinet.com/blog/threat-research/affiliates-cookbook-firsthand-peek-into-operations-and-tradecraft-of-conti; https://www.crowdstrike.com/blog/magniber-ransomware-caught-using-printni
VulnCheck
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-1675 [HIGH] CWE-285 Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.fortinet.com/blog/threat-research/affiliates-cookbook-firsthand-peek-into-operations-and-tradecraft-of-conti; https://blog.talosintelligence.com/2021/08/vice-society-ransomware-printnightmare.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://download.ahnlab.com/global/brochure/Analysis%20Report%20of%20Kimsuky%20Group.pdf; https://www.advintel.io/post/ransomware-advisory-log4shell-exploitation-for-initial-acc
CISA
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
cisa·2024-04-23·CVSS 7.8
CVE-2022-38028 [HIGH] Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028; https://nvd.nist.gov/vuln/detail/CVE-2022-38028
Remediation Due Date: 2024-05-14
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2022-10-11·CVSS 7.8
CVE-2022-38028 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018419
Reference: https://support.microsoft.com/help/5018419
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5018410
Reference: https://suppor
YARA
Windows_Exploit_CVE_2022_38028_31fdb122
yara·CVSS 7.8
CVE-2022-38028 [HIGH] Windows_Exploit_CVE_2022_38028_31fdb122
rule Windows_Exploit_CVE_2022_38028_31fdb122 {
meta:
author = "Elastic Security"
id = "31fdb122-36fd-4fae-b605-542dc344575c"
fingerprint = "e489287412ee673f4d93c5efc9e61b5d26d877bb0f4ddf827926b4d5d87dc399"
creation_date = "2024-06-06"
last_modified = "2024-06-12"
threat_name = "Windows.Exploit.CVE-2022-38028"
reference_sample = "6b311c0a977d21e772ac4e99762234da852bbf84293386fbe78622a96c0b052f"
severity = 100
arch_context = "x86"
scan_context = "file, memory"
license = "Elastic License v2"
os = "windows"
strings:
$a = { 70 72 69 6E 74 54 69 63 6B 65 74 2E 58 6D 6C 4E 6F 64 65 2E 6C 6F 61 64 28 27 25 53 3A 2F 2F 67 6F 27 29 3B }
condition:
all of them
}
Elastic
Potential privilege escalation via CVE-2022-38028
elastic_rules·CVSS 7.8
CVE-2022-38028 [HIGH] Potential privilege escalation via CVE-2022-38028
Potential privilege escalation via CVE-2022-38028
Identifies a privilege escalation attempt via exploiting CVE-2022-38028 to hijack the print spooler service execution.
Query:
file where host.os.type == "windows" and event.type != "deletion" and
file.name : "MPDW-constraints.js" and
file.path : (
"?:\\*\\Windows\\system32\\DriverStore\\FileRepository\\*\\MPDW-constraints.js",
"?:\\*\\Windows\\WinSxS\\amd64_microsoft-windows-printing-printtopdf_*\\MPDW-constraints.js",
"\\Device\\HarddiskVolume*\\*\\Windows\\system32\\DriverStore\\FileRepository\\*\\MPDW-constraints.js",
"\\Device\\HarddiskVolume*\\*\\Windows\\WinSxS\\amd64_microsoft-windows-printing-printtopdf_*\\MPDW-constraints.js"
) and
not process.executable : (
"?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
"?:\\Windows\\System32\\tas
No public exploits indexed.
Volexity
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
blogs_volexity·2024-11-22
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
Threat Intelligence
## The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
November 22, 2024
Sean Koessel, Steven Adair, and Tom Lancaster
In early February 2022, notably just ahead of the Russian invasion of Ukraine , Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever worked. The investigation began when an alert from a custom detection signature Volexity had deployed at a customer site (“Organization A”) indicated a threat actor had compromised a server on the customer’s network. While Volexity quickly investigated the threat activity, more questions were raised than answers due to a very motivated and skilled advanced persistent threat (APT) actor, who was using a novel
Bleepingcomputer
Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
blogs_bleepingcomputer·2024-11-22
Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
## Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
## Bill Toulas
Russian state hackers APT28 (Fancy Bear/Forest Blizzard/Sofacy) breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique called "nearest neighbor attack."
The threat actor pivoted to the target after first compromising an organization in a nearby building within the WiFi range.
The attack was discovered on February 4, 2022, when cybersecurity company Volexity detected a server compromise at a customer site in Washington, DC that was doing Ukrainian-related work.
APT28 is part of Russia's military unit 26165 in the General Staff Main Intelligence Directorate (GRU) and has been conducting cyber operations since at least 2004
Volexity
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
blogs_volexity·2024-11-22
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
Threat Intelligence
# The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
November 22, 2024
Sean Koessel, Steven Adair, and Tom Lancaster
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever worked. The investigation began when an alert from a custom detection signature Volexity had deployed at a customer site (“Organization A”) indicated a threat actor had compromised a server on the customer’s network. While Volexity quickly investigated the threat activity, more questions were raised than answers due to a very motivated and skilled advanced persistent threat (APT) actor, who was using a novel a
Wiz
Crying Out Cloud - May 2024 Newsletter | Wiz
blogs_wiz·2024-05-06·CVSS 10.0
[CRITICAL] Crying Out Cloud - May 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks of cloud security highlights!
## 🔎 Highlights
Architecture Risks that May Compromise AI-as-a-Service Providers
Wiz research recently performed a security audit of Hugging Face and discovered several security issues that would have allowed an actor running a specially-crafted malicious model on Hugging Face's infrastructure to achieve remote code execution and cross-tenant access to other customers' spaces or models. All these issues were remediated by Hugging Face and no customer action is required.
Learn more in our blog .
## 🐞 High Profile Vulnerabilities
DoS Vulnerability in HTTP/2 CONTINUATION Frames
Checkpoint
29th April – Threat Intelligence Report
blogs_checkpoint·2024-04-29
CVE-2024-4040 29th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th April, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Germany has revealed a sophisticated state-sponsored hacking campaign targeting Volkswagen, orchestrated by Chinese hackers since 2010. The attackers successfully infiltrated VW’s networks multiple times, extracting thousands of documents critical to automotive technology, including electric and hydrogen vehicle innovations.
Talos
The private sector probably isn’t coming to save the NVD
blogs_talos·2024-04-25
The private sector probably isn’t coming to save the NVD
## The private sector probably isn’t coming to save the NVD
I wrote last week about the problems arising from the massive backlog of vulnerabilities at the U.S. National Vulnerability Database.
Thousands of CVEs are still without analysis data , and the once-reliable database of every single vulnerability that’s disclosed and/or patched is now so far behind, it could take up to 100 days for the National Institute of Standards and Technology (NIST) to catch up, and that would be assuming no new vulnerabilities are disclosed during that period.
While the U.S. government and NIST try to sort out a potential solution, and hopefully await more funding and restructuring, NIST says it’s hoping to launch a consortium to help either rebuild the NVD or create a replacement.
Other security expert
Talos
The private sector probably isn’t coming to save the NVD
blogs_talos·2024-04-25
The private sector probably isn’t coming to save the NVD
I wrote last week about the problems arising from the massive backlog of vulnerabilities at the U.S. National Vulnerability Database.
Thousands of CVEs are still without analysis data, and the once-reliable database of every single vulnerability that’s disclosed and/or patched is now so far behind, it could take up to 100 days for the National Institute of Standards and Technology (NIST) to catch up, and that would be assuming no new vulnerabilities are disclosed during that period.
While the U.S. government and NIST try to sort out a potential solution, and hopefully await more funding and restructuring, NIST says it’s hoping to launch a consortium to help either rebuild the NVD or create a replacement.
Other security experts have floated the idea of other companies or organizations cr
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
blogs_tenable·2023-01-10·CVSS 8.8
[HIGH] Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s October 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-41033)
blogs_tenable·2022-10-11·CVSS 7.8
[HIGH] Microsoft’s October 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-41033)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Threat Intel
APT28 (APT28, IRON TWILIGHT, SNAKEMACKEREL)
threat_intel
APT28 (APT28, IRON TWILIGHT, SNAKEMACKEREL)
# Threat Actor Profile: APT28
ATT&CK ID: G0007
Also known as: APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
Suspected origin: Russia
## Overview
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-412
ATT&CK
APT28 Nearest Neighbor Campaign
mitre_attack·CVSS 7.8
CVE-2022-38028 [HIGH] APT28 Nearest Neighbor Campaign
APT28 Nearest Neighbor Campaign
[APT28 Nearest Neighbor Campaign](https://attack.mitre.org/campaigns/C0051) was conducted by [APT28](https://attack.mitre.org/groups/G0007) from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.(Citation: Nearest
2022-10-11
Published
2024-04-23
Added to CISA KEV
Exploited in the wild