Poland’s CERT.PL and the Military Counterintelligence Service disclosed a phishing-based espionage campaign targeting diplomatic personnel and attributed it to APT29, also tracked as Nobelium and Cozy Bear. The operation used phishing lures to deliver multiple malware families, including HALFRIG, QUARTERRIG, and SNOWYAMBER, with ENVYSCOUT commonly serving as the delivery script before follow-on activity involving Cobalt Strike or Brute Ratel.
SecurityScorecard’s STRIKE Team reviewed related indicators and network traffic tied to the campaign but said the infrastructure evidence was not conclusive because the same hosting IPs also supported unrelated domains and much of the observed traffic traversed large hosting providers. Even so, some transfer patterns involving IP space in the United States, United Kingdom, and Germany were assessed as potentially consistent with diplomatic targeting aligned with Russian intelligence interests.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers first observed QUARTERRIG in March 2023. The malware shares code overlap with HALFRIG but uses different obfuscation methods.
Analysts first observed the HALFRIG malware family in February 2023. HALFRIG deploys Cobalt Strike and uses encrypted shellcode rather than downloading its second-stage payload through command-and-control.
A new version of SNOWYAMBER with added operational security features appeared in February 2023. The malware is associated with later-stage deployment of Cobalt Strike and BruteRatel.
The malware family SNOWYAMBER was first observed in October 2022. It functions as a dropper and uses Notion for communications.
CERT.PL and Poland’s Military Counterintelligence Service released joint advisories on April 13 about newly observed espionage activity targeting diplomatic personnel through phishing emails. The advisories attributed the campaign to APT29 and documented the malware families HALFRIG, QUARTERRIG, and SNOWYAMBER along with indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.