QUARTERRIG

QUARTERRIGQUARTERRIG

Description

A tool first used in March 2023, sharing part of the code with HALFRIG. Two versions of this tool were observed. QUARTERRIG is a dropper that was used in an espionage campaign significantly overlapping with publicly described activity linked to the APT29 and NOBELIUM activity sets. QUARTERRIG does not contain any other capabilities aside from downloading and executing 2nd stage. To bypass security products, QUARTERRIG heavily relies on obfuscation based on opaque predicates and multi-stage execution, interweaving shellcode and PE files. HALFRIG and QUARTERRIG share some of the codebase, suggesting that QUARTERRIG authors have access to both HALFRIG source code and the same obfuscation libraries.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
HALFRIG
Software
SNOWYAMBER
Software
QUADAGENT
Software
QUASARRAT
Actor
HollowQuill
Software
SLOWDRIFT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.