Equation Group is a long-running, highly sophisticated cyberespionage actor widely linked in public reporting to the United States National Security Agency, including its Tailored Access Operations mission. Also known as Equation, the group has conducted computer network exploitation operations since at least 2001, with evidence suggesting activity may date to the late 1990s. Its operations have targeted government, military, telecommunications, energy, aerospace, nuclear research, financial, transportation, media, technology, and academic organizations across numerous countries. The group operates a mature, modular multi-platform intrusion capability spanning Windows, Linux, Solaris, macOS, FreeBSD, JunOS, and network infrastructure. Known malware platforms include EquationLaser, EquationDrug, DoubleFantasy, TripleFantasy, Fanny, GrayFish, and Bvp47. EquationDrug combines kernel- and user-mode components, rootkit concealment, encrypted configuration and storage, plugin-based collection, network interception, browser and credential collection, keylogging, removable-media monitoring, and disk-firmware manipulation. Fanny supports USB-mediated operations against air-gapped Windows environments. Equation Group tradecraft includes selective victim-specific deployment, covert command-and-control, encrypted communications, passive packet-triggered backdoors, process injection, network traffic interception, host and network reconnaissance, credential and browser-data theft, data collection and exfiltration, persistence, log manipulation, and concealment of files, processes, services, and communications. Leaked tooling associated with the group also demonstrates extensive post-exploitation, exploitation, kernel-level implant, credential-access, keylogging, and network-monitoring capabilities. Shadow Brokers disclosures made portions of the group's alleged exploit frameworks and implants public, enabling substantial downstream criminal reuse of certain capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
64 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The most famous vulnerability is without a doubt CVE-2010-2568, aka the “Stuxnet LNK exploit”. ... Fanny had used that exploit even before Stuxnet ... Flame, Gauss and miniFlame continued to use it afterwards.
...as evidenced with Equation team’s reuse of CVE-2013-3918 within a couple of days of its initial use by the Aurora actors [3].
Resource 106, once decompressed, is a driver called hidsvc.sys. It is loaded into the kernel by invoking the EpMe exploit of CVE-2017-0005 (this is the very same exploit that had its logic find its way into the Jian exploit somehow).
each of those systems were hit by tools handed down from the Equation Group and Shadow Brokers, namely EternalBlue and DoublePulsar... IDS rules, viz. MS17-010 TRANS2 SECONDARY REQUEST and MS17-010 Echo Response. They were all found to be attempts to exploit SMB vulnerabilities.
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Its OS X implant appears to include logic suggesting a dylib-based variant loaded via DYLD_INSERT_LIBRARIES, removing that environment variable before spawning child processes to avoid unintended propagation.
Named as the alleged actor behind the leaked tools and exploits attributed in the dump.
Sophisticated NSA-associated cyber operation whose offensive tools were allegedly stolen and leaked by Shadow Brokers.
Shadowy hacking operation widely believed to be run by the NSA; its offensive cyber tools were allegedly stolen and leaked by the Shadow Brokers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.