The Shadow Brokers, also known as ShadowBrokers and Shadow Brokers, is an unidentified group known for publishing and attempting to auction stolen offensive cyber tools associated with the Equation Group and the United States National Security Agency. The group emerged publicly in August 2016, releasing a sample of exploitation tools and offering additional material for sale in Bitcoin. Its identity, country of origin, state affiliation, and dominant motivation have not been established. The initial releases exposed exploits and implants targeting network infrastructure, including Cisco, Fortinet, WatchGuard, and TOPSEC devices. Published tools included EXTRABACON, EPICBANANA, BENIGNCERTAIN, and the persistent implant JETPLOW. On April 8, 2017, the group published the password for a previously released encrypted archive. Its April 14, 2017 release, titled Lost in Translation, exposed Windows exploitation tools including EternalBlue, EternalRomance, EternalChampion, EternalSynergy, the Fuzzbunch framework, and the DoublePulsar backdoor. Several exposed SMB vulnerabilities had already been addressed by Microsoft's March 2017 MS17-010 update. The disclosures enabled widespread reuse of advanced exploitation capabilities by unrelated threat actors. EternalBlue was subsequently used in the WannaCry outbreak, while other leaked tools appeared in ransomware and espionage operations. These downstream attacks do not establish that the Shadow Brokers operated the resulting campaigns, developed the leaked tools, or used their capabilities against the victims of those campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The new Petya variant appears to be using the MS17-010 Eternal Blue exploit to propagate... Others have confirmed this variant spreads over Windows SMB and is reportedly using the EternalBlue exploit tool, which exploits CVE-2017-0144.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year.
57 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Leak and publication of offensive cyber tools, exploits, vulnerabilities, and operational notes allegedly stolen from the NSA, enabling broader repurposing of advanced capabilities including ransomware distribution.
Mysterious group that surfaced online offering stolen NSA/TAO hacking tools for sale, contributing to public exposure of TAO capabilities.
Released stolen NSA-linked offensive cyber tools, claimed to have breached the Equation Group, attempted to auction the tools, and later publicly dumped them, enabling downstream destructive attacks by other actors.
Enigmatic group that leaked a trove of hacking tools believed to belong to the NSA/Equation Group, likely using the release as a propaganda operation and public dump rather than a genuine auction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.