QUARTERRIG
Aliases: MUSKYBEAT, STATICNOISE
- First seen
- 2022-07-01 00:00:00
- Malware type
- loader, downloader, dropper
- Family
- Malware family
- Profile updated
- 2026-07-07 14:50:48
Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:gb country_code:fr
Context
A stager used by APT29 to download and run CobaltStrike. Here, MUSKYBEAT refers to the in-memory dropper component, while STATICNOISE is the final payload / downloader.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Apt29_Quarterrig (yara-rule)
- MALPEDIA_Win_Quarterrig_Auto (yara-rule)
Reports & references
- Mandiant — Apt29 Evolving Diplomatic Phishing (report)
- go.recordedfuture.com — Cta 2023 0727 1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Quarterrig (report)
- gov.pl — 6F51Bb1A 3Ad2 461C A16D 408915A56F77 (report)