HALFRIG is a malware loader and stager associated with APT29, also known as Nobelium and Cozy Bear, a Russian state-linked cyber-espionage actor widely attributed to the SVR. It was first publicly observed in February 2023 during espionage operations targeting diplomatic personnel, foreign ministries, and related entities, primarily in NATO and EU countries, with some activity also affecting Africa.
HALFRIG is used as part of a phishing-led intrusion chain. Victims are lured with diplomatic-themed spearphishing messages, often impersonating embassies or foreign ministries and directing recipients to compromised websites or malicious attachments. In observed campaigns, the actor commonly used ENVYSCOUT and HTML smuggling to deliver disk-image or archive-based payloads, followed by execution mechanisms such as malicious shortcut files and DLL sideloading.
Functionally, HALFRIG serves as a Cobalt Strike stager. It contains embedded code to run Cobalt Strike and carries encrypted shellcode for the beacon rather than retrieving the next stage from command-and-control infrastructure in the same manner as related tooling such as SNOWYAMBER. Reporting describes HALFRIG as modular, with four components that culminate in staging the beacon on the infected host. It also employs anti-analysis measures, including the use of multiple spawned threads during execution.
HALFRIG forms part of a broader APT29 toolset that included SNOWYAMBER and QUARTERRIG in the same campaign. The malware reflects the actor’s emphasis on stealthy post-compromise access in support of intelligence collection against diplomatic and government targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity involved the distribution of three different strains of malware, HALFRIG, QUARTERRIG, and SNOWYAMBER, through phishing targeting diplomatic personnel.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain first observed in February 2023 that deploys Cobalt Strike on infected systems. It contains encrypted shellcode for its Cobalt Strike beacon and is split into four separate modules responsible for different deployment stages.
A loader first seen in February 2023 that embeds and automatically runs a Cobalt Strike payload.
A stager used to deploy/launch a Cobalt Strike Beacon in APT29 operations.
Stager for Cobalt Strike Beacon used in cyber-espionage campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.