#QUINSTATUS
Malware/Tool
2023-02-16 • Slick Phish & Cartoon Animals
QUINSTATUS is malware linked by Mandiant to DPRK-nexus activity and observed in pharmaceutical targeting. A February 2022 sample was dropped from a malicious document likely aimed at a major pharmaceutical company and carried a digital signature created with a compromised Osprey Video certificate. Analysis of recent and older related samples connected QUINSTATUS with the MARBLEROCK and SWEETPEA malware families. The activity combined malicious-document delivery, abuse of a stolen code-signing identity, and targeting of a high-value pharmaceutical organization.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days