The Shadow Brokers, also styled TheShadowBrokers, is a group known for publicly releasing collections of exploitation tools and other material it claimed to have stolen from the Equation cyberespionage group and associated with the United States National Security Agency. Its identity, country of origin, and state affiliation are not established. The group advertised disclosed material as a sample and proposed auctioning additional files to the highest bidder. On April 8, 2017, it released the “Dont Forget Your Base” collection, consisting primarily of tools and scripts. On April 14, 2017, it released “Lost In Translation,” which included exploits targeting Microsoft Windows and other enterprise software. The disclosed collections contained tools targeting Windows network services, messaging platforms, network appliances, and Unix-like systems. Several Windows exploits addressed vulnerabilities covered by Microsoft's MS17-010 security update. Exploitation capabilities disclosed by the group subsequently contributed to the spread of the WannaCry ransomware outbreak. This connection does not establish that The Shadow Brokers operated WannaCry or conducted ransomware attacks. Its demonstrated activity centers on publishing and offering purportedly stolen offensive tooling; the original acquisition method and any direct intrusion operations remain unestablished.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed to have hacked Equation and stolen its exploits and operational tools. Released multiple collections, including the April 8, 2017 tools-and-scripts dump and the April 14 Windows exploit dump. Described released material as a sample and announced plans to auction the 'best' files. The reference does not establish that TheShadowBrokers operationally used the disclosed malware or vulnerabilities.
Published alleged NSA hacking tools that exposed security holes later associated with the WannaCry outbreak.
Published/disclosed alleged NSA hacking tools and related vulnerabilities that were later leveraged in the WannaCry ransomware outbreak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.