DoublePulsar is a memory-resident Windows kernel-mode backdoor supporting x86 and x64 systems. It was included in the Fuzzbunch toolkit released by the Shadow Brokers in April 2017. Attackers commonly install it after exploiting Windows SMB vulnerabilities with tools such as EternalBlue, establishing a foothold for remote payload execution and subsequent malware deployment. DoublePulsar is an implant rather than the vulnerability exploit itself.
The backdoor communicates through SMB or RDP. Its SMB implementation hooks a server function table and interprets specially crafted requests as commands to check installation status, execute arbitrary shellcode, load DLL payloads, or uninstall the implant. It can inject DLLs into user-mode processes through asynchronous procedure calls and evade PatchGuard. Payloads can be processed in memory without being written to disk. The implant is volatile and is removed by rebooting; installing SMB security updates without restarting an infected system can leave an existing implant active.
DoublePulsar has been used to deliver WannaCry ransomware and support network propagation chains involving EternalRocks, BlackSquid, and Lucifer. It was also incorporated into attempted Ragnarok ransomware deployment following Sophos XG firewall compromises and deployed in an intrusion against an NCR Aloha restaurant point-of-sale environment. BackdoorDiplomacy has used the leaked implant in its operations. Its reuse spans espionage and financially motivated attacks against Windows workstations and servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The report's “IoT attacks blocked by Armor” chart includes the detection label “SMB.CVE-2017-0143.DoublePulsar.”
The cmcAgent’s RUNCommand function allows for a parameter to be supplied in a specially crafted XML request that can be executed remotely if the server is configured to listen on TCP port 8089 for incoming connections. Passing such a command allows the attacker to execute that command as SYSTEM.
EternalBlue exploits (MS17-010) CVE-2017-0144. There is a buffer overflow caused by a memmove operation, which leads to a mathematical error, where a DWORD is being cast to a WORD.
The ransomware perpetrators incorporated publicly-available exploit code for the patched SMB EternalBlue vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMB server.
An attacker discovered an SQL injection vulnerability (CVE-2020-12271) in the Sophos XG firewall. Attackers used the zero-day to plant malware on the device and subsequently changed their attack routine to deploy ransomware.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
Symantec reported that two of those advanced hacking tools were used against a host of targets starting in March 2016... an advanced persistent threat hacking group... somehow got access to a variant of the NSA-developed “DoublePulsar” backdoor and one of the Windows exploits the NSA used to remotely install it on targeted computers.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
During our analysis, we also discovered that Amadey was actively pushing the Remcos RAT via its control panel... We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine.
Once DoublePulsar is installed, a PowerShell command is executed, and contact is made with the Beapy command and control (C&C) server, before a coinminer is downloaded onto the target computer.
Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor opened via EternalBlue and used in the WannaCry intrusion chain to locate accessible targets and deliver ransomware.
Kernel-level backdoor/implant from the leaked Shadow Brokers dump, reachable via port-knocking over RDP/SMB and described as difficult to detect. It is also installed post-exploitation by WannaCry before the ransomware component is loaded.
A well-known kernel implant referenced as design inspiration for NebulaPulsar’s resident implant model.
Backdoor implant referenced as part of exploit chains used in pre-compromised environments that Sandworm later leveraged to move deeper into industrial networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.