Equation Group, also known as Equation, is a highly sophisticated, well-resourced cyberespionage actor widely assessed to be associated with the United States National Security Agency. It conducts covert intrusions against organizations in multiple countries. Its operations have included targeting Middle Eastern financial transaction providers and institutions, and it has technical links to the Stuxnet operation against Iranian nuclear infrastructure. The group's arsenal spans Windows, Linux, macOS, Unix systems, and network appliances. It includes remote-code-execution and local privilege-escalation exploits, modular post-exploitation frameworks, persistent implants, kernel-level backdoors, rootkits, keyloggers, and network-interception utilities. Associated tools include the Fuzzbunch exploit platform, DanderSpritz post-exploitation framework, DoublePulsar kernel payload, NOPEN remote-access tool, JETPLOW firewall implant, and Grayfish malware platform. Its tradecraft includes encrypted communications, concealed control channels, log manipulation, timestamp alteration, and exploitation of vulnerable drivers for kernel execution. Beginning in 2016, the separate Shadow Brokers group disclosed collections of tools attributed to Equation Group. The releases exposed exploits against Cisco firewalls, Microsoft Windows SMB services, and numerous enterprise applications. Publicly released exploits, including EternalBlue and EternalRomance, were subsequently repurposed by unrelated actors in ransomware and destructive campaigns; those downstream operations are not attributable to Equation Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
65 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
56 malware families attributed to this actor across reporting.
51 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The most famous vulnerability is without a doubt CVE-2010-2568, aka the “Stuxnet LNK exploit”. ... Fanny had used that exploit even before Stuxnet ... Flame, Gauss and miniFlame continued to use it afterwards.
...as evidenced with Equation team’s reuse of CVE-2013-3918 within a couple of days of its initial use by the Aurora actors [3].
Resource 106, once decompressed, is a driver called hidsvc.sys. It is loaded into the kernel by invoking the EpMe exploit of CVE-2017-0005 (this is the very same exploit that had its logic find its way into the Jian exploit somehow).
each of those systems were hit by tools handed down from the Equation Group and Shadow Brokers, namely EternalBlue and DoublePulsar... IDS rules, viz. MS17-010 TRANS2 SECONDARY REQUEST and MS17-010 Echo Response. They were all found to be attempts to exploit SMB vulnerabilities.
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
U.S.-intelligence-linked actor associated with the Stuxnet operation against Iranian nuclear infrastructure.
Its OS X implant appears to include logic suggesting a dylib-based variant loaded via DYLD_INSERT_LIBRARIES, removing that environment variable before spawning child processes to avoid unintended propagation.
Named as the alleged actor behind the leaked tools and exploits attributed in the dump.
Sophisticated NSA-associated cyber operation whose offensive tools were allegedly stolen and leaked by Shadow Brokers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.