Equation Group is a highly sophisticated state-sponsored cyber espionage actor widely assessed to be linked to the United States National Security Agency, including its Tailored Access Operations mission set. Public reporting places its activity at least as far back as the early 2000s, with some assessments suggesting roots in the 1990s. The actor is known for exceptionally advanced malware engineering, deep persistence mechanisms, modular espionage platforms, and close technical relationships with other elite operations including Stuxnet, Flame, Duqu, Fanny, and GrayFish. Equation Group has operated complex multi-component intrusion frameworks rather than simple standalone implants. Its best-known platforms include EquationDrug and GrayFish, supported by numerous user-mode and kernel-mode modules for surveillance, covert command execution, traffic interception, credential theft, keylogging, browser monitoring, removable-media monitoring, passive backdoor access, and encrypted data staging prior to exfiltration. The actor has also demonstrated firmware-level tradecraft, including tooling designed to identify specific hard drives and interact with storage hardware at a low level, as well as capabilities associated with hard-drive firmware persistence and manipulation. The group’s tooling shows strong emphasis on stealth, anti-analysis, and controlled deployment. Reported techniques include custom string obfuscation, hidden ordinal-only exports, malformed or deceptive API parameters, rootkit functionality, audit-log suppression, passive network backdoors, and manual or semi-manual loading chains for sensitive payloads. Analysis of the nls_933w.dll and embedded WIN32M driver family indicates the actor used custom IOCTL-based communication with kernel drivers and ATA command workflows to interrogate storage devices and gate execution based on vendor characteristics. Other reporting describes tools used to search attached hard drives for characteristics relevant to firmware overwrite or persistence operations. Equation Group has also used reconnaissance against connected hardware and removable media, including discovery of attached drives and monitoring of peripheral or storage environments. Its malware ecosystem includes kernel and user components for persistence, process and driver management, network sniffing, and post-exploitation collection. The actor’s operational style is consistent with long-term clandestine access, victim-specific customization, and high-value intelligence collection rather than disruptive or financially motivated crime. Aliases and related naming include Equation and Equation Group. The actor is frequently discussed alongside NSA-linked operations and has been associated in public research with exploit sharing and developmental overlap involving Stuxnet-era tooling, including the Fanny worm and technical links to Flame and Duqu.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sophisticated NSA-associated cyber operation whose offensive tools were allegedly stolen and leaked by Shadow Brokers.
Shadowy hacking operation widely believed to be run by the NSA; its offensive cyber tools were allegedly stolen and leaked by the Shadow Brokers.
The content references Equation Group only as a tag and does not provide substantive details about its activity in the article body.
Associated with the Fast16 cyber sabotage framework, a precision industrial sabotage platform targeting engineering and simulation software by patching floating-point arithmetic routines to subtly alter modeling results.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.