This is the second local privilege-escalation zero-day this APT group has exploited.
Source: Threadpost