EquationDrug is a long-running, highly modular cyberespionage platform associated with the Equation Group and in use since at least 2003. It is widely regarded as one of the group’s principal Windows espionage frameworks, succeeding EquationLaser and later being superseded for some operations by GrayFish. The platform is designed for selective, victim-specific deployment rather than indiscriminate mass infection and reflects the tradecraft of a mature nation-state intrusion capability.
Architecturally, EquationDrug combines kernel-mode and user-mode components with a plugin-based framework that allows operators to tailor functionality per target. Its startup chain includes low-level components for older and newer Windows generations, a user-mode loader, and a central orchestrator that manages configuration, module loading, and tasking. The platform uses encrypted configuration storage and an encrypted virtual file system to stage collected data prior to exfiltration. Multiple components implement stealth and survivability features, including rootkit functionality, hidden or protected objects, process injection, suppression of audit logging, and passive network backdoor behavior triggered by crafted traffic.
Observed capabilities include system profiling, file and directory collection, screenshot capture, keylogging, clipboard monitoring, browser activity monitoring, browser history and autofill theft, cached password collection, WMI-based collection, reverse DNS resolution, process and file management, network sniffing and interception, removable-media monitoring, NTFS-level access and disk forensics, and manipulation of HDD and SSD firmware. The framework’s plugin ecosystem also supports multiple communications methods and covert data handling. These features make EquationDrug a full espionage platform rather than a simple standalone Trojan.
EquationDrug primarily targets Windows systems, including legacy Windows families as well as NT-based versions. Reporting has also linked Equation Group tooling more broadly to Linux and Solaris operations, but the high-confidence characterization of EquationDrug itself is as a Windows espionage framework. The malware is notable for its longevity, engineering sophistication, and extensive modularity, and remains one of the best-known examples of advanced state-sponsored surveillance malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EquationDrug is one of the main espionage platforms used by the Equation Group... EquationDrug, which is still in use, dates back to 2003, although the more modern GrayFish platform is being pushed to new victims.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The driver acts as the first stage of the EquationDrug platform on Windows 2000+ and implements rootkit functions for hiding the components of the platform.
Next, it crafts and injects a shellcode in “services.exe” or “winlogon.exe”. The shellcode is designed to spawn the loader process from the executable called “mscfg32.exe”.
Code Patcher The driver patches OS code to dynamically disable or enable Windows audit logging.
The rootkit code in the driver hooks several Native API functions that lets it hide or protect registry keys, files and running processes.
System information gathering: OS version Computer name User name Locale Keyboard layout Timezone Process list
System information gathering: OS version Computer name User name Locale Keyboard layout Timezone Process list
Many encryption algorithms used in communication and information... Network communication encryption... This sub key is used for encrypting and decrypting to send and receive data.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alternate name used by Kaspersky for UnitedRake; mentioned for naming context rather than as a separate malware family in this article.
Equation group implant named as part of the group's malware arsenal.
Known Equation Group malware/toolset referenced as part of Kaspersky’s prior findings and used for code-comparison against the ShadowBrokers leak, specifically around a rare RC5/RC6 implementation.
A modular cyberespionage platform used for long-term covert access, data theft, surveillance, and system management via numerous plugins. Capabilities include file collection, screenshots, network interception, password theft, browser monitoring, keylogging, removable media monitoring, NTFS access, and HDD/SSD firmware manipulation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.