HALFRIG is a Windows malware loader and Cobalt Strike Beacon stager first observed in February 2023. It is associated with APT29, also known as NOBELIUM and Cozy Bear, a cyberespionage group attributed to Russia’s Foreign Intelligence Service. HALFRIG has been deployed against diplomatic personnel in campaigns targeting foreign ministries, diplomatic missions, and related organizations, primarily in NATO and European Union countries.
HALFRIG comprises four modules that culminate in staging Cobalt Strike Beacon. It carries encrypted Beacon shellcode within its components rather than retrieving the second-stage payload from a remote command-and-control service. Its execution uses multiple spawned threads as an anti-analysis measure. The related QUARTERRIG family shares portions of HALFRIG’s code but employs different obfuscation techniques.
Distribution involves spearphishing messages impersonating diplomatic correspondence and using meeting invitations or document-collaboration lures. Campaign delivery chains use compromised websites and the ENVYSCOUT script for HTML smuggling, with malicious files packaged in archives or disk images. Signed executables are abused through DLL sideloading to execute malicious libraries and stage subsequent payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity involved the distribution of three different strains of malware, HALFRIG, QUARTERRIG, and SNOWYAMBER, through phishing targeting diplomatic personnel.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain first observed in February 2023 that deploys Cobalt Strike on infected systems. It contains encrypted shellcode for its Cobalt Strike beacon and is split into four separate modules responsible for different deployment stages.
Mentioned only as the predecessor from which QUARTERRIG evolved. The article does not separately describe HALFRIG's functionality, delivery mechanism, or discovery date.
A loader first seen in February 2023 that embeds and automatically runs a Cobalt Strike payload.
A stager used to deploy/launch a Cobalt Strike Beacon in APT29 operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.