Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new sample has been uploaded to VirusTotal, and its characteristics strongly resemble QUARTERRIG, a malware recently analyzed by CERT.PL and linked to APT29.
We were also able to confirm that the shellcode contained overlaps with the fourth-stage shellcode dropper loader, shown in Figure 7, as described in the Cloaked Ursa QUARTERRIG malware report by Military Counterintelligence Service and CERT.PL.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
QUARTERRIG instead uses opaque predicates and multi-stage execution combining shellcode and PE files for its obfuscation.
For communication, the payload uses both the Microsoft Graph and Dropbox API... If communication fails via the Graph API several times, communication via Dropbox is attempted.
If the infected workstation passed manual verification, the aforementioned downloaders were used to deliver and start-up the commercial tools COBALT STRIKE or BRUTE RATEL.
Previously, Cloaked Ursa-linked payloads that communicate with Dropbox had wrapped communications in a packet that resembled an MP3 file... In this sample, it appears that they have opted to use BMP files. The threat actor-owned C2 will upload commands to Dropbox that are wrapped in the BMP format.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain first observed in March 2023. Its code overlaps with HALFRIG, but it uses different obfuscation methods, including opaque predicates and multi-stage execution combining shellcode and PE files.
A Cloaked Ursa-linked malware/loader family referenced for code overlap with the observed shellcode. It uses staged shellcode loading and is associated with obfuscated payload delivery and C2 functionality.
Malware linked to APT29 whose updated loader is examined in the Information campaign. Delivered through an email-linked ISO, it uses a legitimate Microsoft-signed executable to side-load a malicious DLL and execute shellcode from dbg.info. The updated loader randomly selects a suitable, previously unloaded system DLL, maps it into memory, overwrites its .text section with shellcode, and restores executable-read permissions. The analyzed sample communicates with pizzais.com/order.php and uses a current-user Run registry key for persistence. The article describes the sample as strongly resembling QUARTERRIG rather than conclusively identifying it.
A downloader first used in March 2023 that shares code with HALFRIG and was used to profile victims and deliver follow-on payloads after manual verification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.