TheShadowBrokers is a mysterious intrusion-related persona or group best known for repeatedly publishing what it claimed were offensive cyber tools and exploit material associated with the U.S. National Security Agency. The actor is notable for enabling downstream criminal and disruptive activity by exposing high-impact exploitation capabilities to the public. Material attributed to TheShadowBrokers included Windows exploitation components later linked in reporting to the WannaCry ransomware outbreak, which used leaked vulnerability information and exploit tooling to propagate automatically across vulnerable systems. Publicly available information in this context supports characterization of TheShadowBrokers primarily as a leak-and-disclosure actor rather than a conventional ransomware operator. High-confidence details about its membership, state affiliation, operational base, and direct victimology are not available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Published alleged NSA hacking tools that exposed security holes later associated with the WannaCry outbreak.
Published/disclosed alleged NSA hacking tools and related vulnerabilities that were later leveraged in the WannaCry ransomware outbreak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.