Fanny is an Equation Group worm used for espionage and for compromising air-gapped Windows environments. Active by 2008, it collected information from targets in the Middle East and Asia and is regarded as one of the earliest known nation-state frameworks built to bridge air gaps through removable media. It used USB drives as both an infection vector and an offline command-and-control and exfiltration channel, including a hidden storage area on the drive to shuttle data between isolated systems and internet-connected staging hosts.
Fanny is notable for using two zero-day exploits and for sharing exploit lineage with Stuxnet. It used the Windows LNK vulnerability CVE-2010-2568 to gain execution from USB media, and reporting has linked it to another exploit later associated with Stuxnet-era tooling. The malware was designed to profile infected hosts and collect reconnaissance from isolated networks, after which operators could use the USB-based mechanism to retrieve stolen data and potentially relay tasking back into the air-gapped environment.
Fanny is associated with the Equation Group and is part of a broader ecosystem that includes DoubleFantasy, EquationDrug, TripleFantasy, GrayFish, and EquationLaser. Some victims were reportedly upgraded from Fanny to DoubleFantasy and then to EquationDrug, indicating its role as an early-stage access and reconnaissance component within a larger intrusion chain. Its use against air-gapped targets, removable-media propagation, and espionage-focused collection make it a significant precursor in the evolution of advanced USB-borne cyber operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The most famous vulnerability is without a doubt CVE-2010-2568, aka the “Stuxnet LNK exploit”. ... Fanny had used that exploit even before Stuxnet ... Flame, Gauss and miniFlame continued to use it afterwards. | Fanny was one of oldest frameworks to compromise air-gapped networks ... sporting two powerful zero day exploits ... and a hidden storage space altering the filesystem of the drive for a covert communication channel and exfiltration point.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A computer worm created in 2008 and used to collect information about targets in the Middle East and Asia. Some victims appear to have been upgraded first to DoubleFantasy, and then to EQUATIONDRUG.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm referenced for its exploits, which were later tied into the broader connections among Stuxnet, Duqu, and the Equation group.
Equation group implant named as part of the group's malware arsenal.
An Equation Group worm said to have used two Stuxnet zero-days one to two years before Stuxnet, helping connect Equation to the broader malware cluster discussed.
An Equation Group worm that used two Stuxnet zero-days 1–2 years before Stuxnet appeared, helping connect Equation to the broader collaborative cluster discussed in the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.