APT28__2024__logpoint-etpr-forest-blizzard.pdf
ID: deafd8c2-55b5-46be-90bb-79214e235e04
STIX ID: report--deafd8c2-55b5-46be-90bb-79214e235e04
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2024-05-31
Last Modified Date: 2024-05-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Logpoint ETP report analyzes Forest Blizzard (APT28), a Russian-linked espionage group, describing historical and recent campaigns, a detailed technical breakdown of the GooseEgg Print Spooler exploit and associated binaries (justice.exe, DefragmentSrv.exe, wayzgoose DLLs), multiple CVE exploitations (e.g., CVE-2022-30190 Follina, CVE-2023-23397, CVE-2023-38831), observed IOCs and attack chains against government and critical infrastructure targets, and provides detection queries and response playbooks for Logpoint SOAR/AgentX to hunt, investigate, and remediate infections.
