QUARTERRIG

Aliases: MUSKYBEAT, STATICNOISE

First seen
2022-07-01 00:00:00
Malware type
loader, downloader, dropper
Family
Malware family
Profile updated
2026-07-07 14:50:48

Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:gb country_code:fr

Context

A stager used by APT29 to download and run CobaltStrike. Here, MUSKYBEAT refers to the in-memory dropper component, while STATICNOISE is the final payload / downloader.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Apt29_Quarterrig (yara-rule)
  • MALPEDIA_Win_Quarterrig_Auto (yara-rule)

Reports & references

  • Mandiant — Apt29 Evolving Diplomatic Phishing (report)
  • go.recordedfuture.com — Cta 2023 0727 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Quarterrig (report)
  • gov.pl — 6F51Bb1A 3Ad2 461C A16D 408915A56F77 (report)

External references