logo

APT28__2024__logpoint-etpr-forest-blizzard.pdf

ID: deafd8c2-55b5-46be-90bb-79214e235e04

STIX ID: report--deafd8c2-55b5-46be-90bb-79214e235e04

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2024-05-31

Last Modified Date: 2024-05-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Logpoint ETP report analyzes Forest Blizzard (APT28), a Russian-linked espionage group, describing historical and recent campaigns, a detailed technical breakdown of the GooseEgg Print Spooler exploit and associated binaries (justice.exe, DefragmentSrv.exe, wayzgoose DLLs), multiple CVE exploitations (e.g., CVE-2022-30190 Follina, CVE-2023-23397, CVE-2023-38831), observed IOCs and attack chains against government and critical infrastructure targets, and provides detection queries and response playbooks for Logpoint SOAR/AgentX to hunt, investigate, and remediate infections.