Equation Group
Equation Group is a highly sophisticated, state-sponsored threat actor widely believed to be associated with the U.S. National Security Agency, and described in some reporting as linked to the NSA’s hacking team or computer surveillance wing. Kaspersky identified it as one of the most advanced hacking operations observed. Reporting in the provided content places its computer network exploitation activity back to at least 2001 and possibly as early as the mid-1990s. Known aliases in the provided content include Equation Group and the locally used Chinese designation APT-C-40 in reference to the NSA’s Tailored Access Operations group. The actor is associated with multiple advanced malware platforms and tooling families in the provided content, including EquationDrug, GrayFish, EquationLaser, DoubleFantasy, FANNY, and fast16. EquationDrug is described as a major long-running espionage platform with a modular plugin architecture, kernel- and user-mode components, encrypted virtual file storage, and capabilities including network interception, reverse DNS, process and driver management, file theft, WMI collection, cached password theft, browser monitoring, NTFS forensics, removable media monitoring, passive network backdoor functionality, HDD/SSD firmware manipulation, keylogging, clipboard monitoring, and browser history and autofill theft. GrayFish is described as a more modern platform that replaced EquationDrug for new victims. Fast16 is described as a sabotage framework linked to signatures in the 2017 Shadow Brokers leak and attributed in the content to Equation Group; it reportedly targeted engineering and simulation software including LS-DYNA and AUTODYN, using a kernel-mode filesystem driver, embedded Lua virtual machine, and rule-based in-memory patching to subtly corrupt simulation results. The content also links Equation Group to offensive infrastructure and exploit tooling exposed through the Shadow Brokers leaks, including SECONDDATE, BADDECISION, BLINDDATE, BANANAGLEE, firewall exploits, router compromise tools, Cisco PIX VPN decryption capabilities, and malware implantation into PC motherboard firmware. Kaspersky reported strong technical links between the leaked tools and prior Equation malware, including a rare RC5/RC6 implementation. The leaked archive contained hundreds of tools and scripts, and researchers assessed them as exceptionally advanced and likely originating from the NSA. Targeting described in the content includes long-term espionage and surveillance operations, as well as specialized sabotage. One article states that leaked material showed specific targeting of Al Quds Bank for Development and Investment in Ramallah, Palestine. Other cited NSA operations using leaked tooling included attacks against Pakistan’s National Telecommunications Corporation and Hezbollah Unit 1800. Fast16-related reporting says the malware was designed to tamper with software believed to be used by Iranian nuclear scientists or nuclear weapons-related simulation environments. The actor is repeatedly discussed in connection with the 2016-2017 Shadow Brokers disclosures, which claimed to have stolen Equation Group tools. Multiple items in the content state that the leaked code bore unique signatures tied to Equation Group and that the leak exposed capabilities later reused in major incidents such as EternalBlue in WannaCry and NotPetya. The content also notes Kaspersky’s 2014 detection of Equation Group malware on a computer believed to belong to an NSA contractor.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Academia & Research
Where they target
Geographies tied to known operations.
- 🇨🇳 China
Where they're from
Attributed origin per open-source reporting.
- US
Tradecraft
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
Observables
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sophisticated NSA-associated cyber operation whose offensive tools were allegedly stolen and leaked by Shadow Brokers.
Shadowy hacking operation widely believed to be run by the NSA; its offensive cyber tools were allegedly stolen and leaked by the Shadow Brokers.
The content references Equation Group only as a tag and does not provide substantive details about its activity in the article body.
Associated with the Fast16 cyber sabotage framework, a precision industrial sabotage platform targeting engineering and simulation software by patching floating-point arithmetic routines to subtly alter modeling results.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.