Shadow Brokers is the name used by an unidentified leak persona or group that emerged publicly in 2016 and became known for publishing offensive cyber tools and documentation widely assessed to have been stolen from the U.S. National Security Agency’s Equation Group and Tailored Access Operations ecosystem. The actor is best characterized as a leak and influence operation rather than a conventional intrusion set with a well-documented victimology or sustained espionage campaign. Its operators have never been publicly identified with certainty, and no individual has been formally charged with conducting the Shadow Brokers leak itself. Known aliases include The Shadow Brokers, shadowbrokers, and shadow_brokers. The persona initially advertised an auction for the stolen material, released samples alongside encrypted archives, and later published substantial portions of the toolset openly. Analysts broadly concluded that the auction framing was likely not a genuine commercial sale. The group’s public communications used deliberately stylized, broken English and were sparse, contributing to the operation’s ambiguity and possible information-operation dimension. The leaked material included highly sophisticated exploitation frameworks, implants, backdoors, and post-exploitation tooling associated with Windows and network infrastructure targeting. Publicly exposed capabilities included EternalBlue, EternalRomance, EternalChampion, EternalSynergy, DoublePulsar, Oddjob, and DarkPulsar. These tools reflected advanced tradecraft such as remote exploitation of SMB vulnerabilities, covert persistence, lateral movement, and modular post-compromise control. Researchers also linked the leaked code to previously documented Equation Group characteristics and to capabilities long associated with elite U.S. signals intelligence operations. Shadow Brokers had outsized strategic impact because its disclosures enabled broad criminal and state reuse of leaked offensive capabilities. EternalBlue in particular was later incorporated into the WannaCry ransomware worm and the NotPetya destructive campaign, demonstrating how leaked nation-state tooling can be rapidly repurposed for global disruptive attacks. Related leaked exploits and techniques were subsequently adapted by researchers and adversaries for wider platform coverage and operational use. Attribution remains unresolved. High-confidence public reporting supports only that the operators are still unidentified. Competing theories have included an insider or former insider with access to NSA materials and a Russian intelligence-linked front or propaganda operation. The latter has often been cited as a leading analytical theory, but it remains unproven in public evidence. Shadow Brokers is therefore best described as an unidentified actor or persona responsible for one of the most consequential public disclosures of advanced state cyber capabilities in modern cybersecurity history.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mysterious group that surfaced online offering stolen NSA/TAO hacking tools for sale, contributing to public exposure of TAO capabilities.
Released stolen NSA-linked offensive cyber tools, claimed to have breached the Equation Group, attempted to auction the tools, and later publicly dumped them, enabling downstream destructive attacks by other actors.
Enigmatic group that leaked a trove of hacking tools believed to belong to the NSA/Equation Group, likely using the release as a propaganda operation and public dump rather than a genuine auction.
Leaked offensive cyber tools including EternalBlue, which enabled the broader WannaCry outbreak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.