#QUINSTATUS

Malware/Tool

2023-02-16 • Slick Phish & Cartoon Animals

QUINSTATUS is malware linked by Mandiant to DPRK-nexus activity and observed in pharmaceutical targeting. A February 2022 sample was dropped from a malicious document likely aimed at a major pharmaceutical company and carried a digital signature created with a compromised Osprey Video certificate. Analysis of recent and older related samples connected QUINSTATUS with the MARBLEROCK and SWEETPEA malware families. The activity combined malicious-document delivery, abuse of a stolen code-signing identity, and targeting of a high-value pharmaceutical organization.

Tagged Reports

« Back