DOUBLEPULSAR is a Windows backdoor implant and kernel-resident post-exploitation component widely associated with the leaked Equation Group toolset. It is most commonly deployed after SMB exploitation, especially via EternalBlue against MS17-010-vulnerable systems, though reporting also describes variants or related implementations communicating over SMB or RDP. The implant operates in memory and has been observed hooking SMB server functionality to interpret specially crafted requests as covert commands. Documented command capabilities include beaconing or presence checks, in-memory DLL execution, shellcode execution, and self-uninstallation.
A defining characteristic of DOUBLEPULSAR is its use as a payload delivery mechanism rather than a standalone intrusion vector. Operators have used it to inject code directly into user processes such as lsass.exe, explorer.exe, and other chosen targets without writing the primary payload to disk. This made it a practical staging implant for follow-on malware including WannaCry, NotPetya-related tooling, coinminers, and other backdoors. Multiple campaigns and malware families have reused or repurposed DOUBLEPULSAR-compatible payloads or leaked implementations, including activity attributed to BackdoorDiplomacy, Glupteba-related infections, Amadey-delivered follow-on payloads, Blackmoon campaign tooling, and enterprise cryptojacking operations such as Beapy.
The implant has been linked to wormable propagation chains because exploit frameworks and malware frequently paired it with EternalBlue to gain remote code execution and then use DOUBLEPULSAR for in-memory payload deployment. In WannaCry-related infections, it was used to deliver launcher code and ransomware components after exploitation. Other reporting describes its use in lateral movement and remote payload injection inside enterprise networks, including delivery of DLLs into remote Windows processes. Because it resides in memory, remediation historically required not only patching the exploited SMB vulnerability but also rebooting infected systems to clear the implant.
DOUBLEPULSAR is best characterized as a memory-resident Windows backdoor used for covert remote code execution and payload staging after successful exploitation. Its enduring significance comes from its role in major 2017 worm outbreaks and from subsequent reuse by a wide range of threat actors who adopted leaked offensive tooling for post-exploitation and lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SMBv1の脆弱性による横展開については、EternalBlueまたはEternalRomance(いずれもMS17-010の更新プログラム適用で修正される)で脆弱性を突き、DoublePulsarを設置、DoublePulsarを介してlsass.exeにインメモリでDLLインジェクションを行います。
the ransomware perpetrators used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMBv1 server. This vulnerability was fixed in security bulletin MS17-010
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
We can also recommend the following script by Luke Jennings, which is designed to sweep a network to find Windows systems compromised with the dumps DOUBLEPULSAR implant... From analysis we did on some implant configuration files, Darkpulsar appears to create a service called ‘dapu’
...systems were hit by tools handed down from the Equation Group and Shadow Brokers, namely EternalBlue and DoublePulsar.
Symantec reported that two of those advanced hacking tools were used against a host of targets starting in March 2016... an advanced persistent threat hacking group... somehow got access to a variant of the NSA-developed “DoublePulsar” backdoor and one of the Windows exploits the NSA used to remotely install it on targeted computers.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
During our analysis, we also discovered that Amadey was actively pushing the Remcos RAT via its control panel... We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine.
The hackers used the NSA’s backdoor, DoublePulsar, to create a persistent backdoor that was used to deliver the WannaCry ransomware.
People [who] have gotten their hands on the tools just started exploiting hosts on the Internet as fast as they could... While security practices almost always dictate the port shouldn’t be exposed to the open Internet...
Once DoublePulsar is installed, a PowerShell command is executed, and contact is made with the Beapy command and control (C&C) server, before a coinminer is downloaded onto the target computer.
it leaves PC vulnerable to remote commands for future attacks.
まず、EternalBlueによるSMBサービスの脆弱性攻撃ですが、カーネルスペースの非ページプール領域でバッファオーバーフローを発生させ、DoublePulsarのシェルコードを動作させます。
Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor opened via EternalBlue and used in the WannaCry intrusion chain to locate accessible targets and deliver ransomware.
A well-known kernel implant referenced as design inspiration for NebulaPulsar’s resident implant model.
Backdoor implant referenced as part of exploit chains used in pre-compromised environments that Sandworm later leveraged to move deeper into industrial networks.
Backdoor component appearing in exploit chains that Sandworm capitalized on in already-compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.