GooseEgg is a custom Windows post-compromise privilege-escalation tool associated with the Russia-linked espionage group Forest Blizzard, also tracked as APT28, Fancy Bear, Sofacy, Sednit, and STRONTIUM, and publicly linked to GRU Unit 26165. It has been used since at least June 2020, and possibly as early as April 2019, in intrusions targeting government, non-governmental, education, and transportation organizations in Ukraine, Western Europe, and North America.
GooseEgg weaponizes CVE-2022-38028 in the Windows Print Spooler service to obtain SYSTEM-level code execution. Reported tradecraft includes modifying a JavaScript constraints file and abusing a rogue protocol handler so that attacker-controlled code is launched by the Print Spooler process with elevated privileges. GooseEgg functions as a launcher that can execute attacker-specified payloads with elevated permissions, enabling follow-on actions after initial compromise.
Observed and reported follow-on uses include credential theft, information theft, remote code execution, backdoor deployment, persistence establishment, and lateral movement. In documented operations, the tool was deployed with supporting scripts that established scheduled-task-based persistence and facilitated collection of credential material from the compromised host. GooseEgg is therefore best understood as a specialized exploitation and privilege-escalation utility used to expand access and enable subsequent espionage activity rather than as a standalone mass-deployed malware family.
Its use fits Forest Blizzard’s long-running pattern of targeted cyber-espionage against public-sector and strategically relevant organizations, combining custom tooling with exploitation of Windows vulnerabilities to deepen access inside victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2024-04-22 ⋅ Microsoft ⋅ Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials GooseEgg
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2024-04-22 ⋅ Microsoft ⋅ Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials GooseEgg
...APT28 (Forrest Blizzard) using a previously unknown hacking tool called GooseEgg.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
This batch script writes the file servtask.bat... The batch script invokes the paired GooseEgg executable and sets up persistence as a scheduled task designed to run servtask.bat.
GooseEgg is typically deployed with a batch script, which we have observed using the name execute.bat and doit.bat. This batch script writes the file servtask.bat...
The malicious activity involves “modifying a JavaScript constraints file and executing it with SYSTEM-level permissions,” according to Microsoft researchers.
The exploit replaces the C: drive symbolic link in the object manager to point to the newly created directory. When the PrintSpooler attempts to load ... MPDW-Constraints.js, it instead is redirected to the actor-controlled directory containing the copied driver packages.
The exploit replaces the C: drive symbolic link in the object manager to point to the newly created directory. When the PrintSpooler attempts to load ... MPDW-Constraints.js, it instead is redirected to the actor-controlled directory containing the copied driver packages.
While a simple launcher application, GooseEgg is capable of spawning other applications specified at the command line with elevated permissions, allowing threat actors to support any follow-on objectives such as remote code execution, installing a backdoor, and moving laterally through compromised networks.
“Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials”.
wayzgoose.dll is a basic launcher application capable of spawning other applications specified at the command line with SYSTEM-level permissions, enabling threat actors to perform other malicious activities such as installing a backdoor, moving laterally through compromised networks, and remotely executing code.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom post-compromise tool used to exploit CVE-2022-38028 to obtain credentials.
A custom Windows privilege-escalation utility used post-compromise to gain SYSTEM-level execution on victim hosts.
A custom-made tool used to exploit a Windows Print Spooler privilege escalation vulnerability, allowing attackers to escalate privileges, steal credentials, enable remote code execution, install backdoors, and move laterally through compromised networks.
A custom Forest Blizzard tool used post-compromise to exploit the Windows Print Spooler vulnerability CVE-2022-38028 for privilege escalation. It launches DLLs or executables with SYSTEM-level permissions, enabling credential theft, remote code execution, persistence, backdoor installation, and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.