Equation Group is a highly sophisticated cyber espionage threat actor widely assessed to be linked to the U.S. National Security Agency, including reporting that associates it with Tailored Access Operations. It is regarded as one of the most advanced known state-sponsored operators, with activity dating to at least the early 2000s and possibly the late 1990s. The group is known for long-term intelligence collection, deep technical tradecraft, and exceptionally mature malware engineering across user mode, kernel mode, boot, firmware, and network layers. Known aliases include Equation and Equation Group. Equation Group has targeted government, military, diplomatic, telecommunications, research, and other strategic entities, with operations associated with high-value espionage and access development. Public reporting has also linked its tooling and development ecosystem to broader state-grade operations involving Stuxnet, Duqu, Flame, Gauss, and the Fanny worm, including exploit sharing and code-development overlaps, though some broader umbrella theories remain less firmly established than the core NSA linkage. The actor is especially notable for modular, stealth-focused platforms such as EquationDrug and GrayFish, as well as supporting implants and drivers that provide persistence, covert execution, traffic interception, credential theft, keylogging, browser monitoring, removable-media monitoring, passive backdoor functionality, and low-level disk operations. Reported capabilities include hidden or encrypted virtual file systems, custom message-passing between components, rootkit functionality, packet sniffing, audit-log suppression, and passive command channels. Equation Group has also been associated with tooling designed to inspect attached storage devices and, in some cases, manipulate hard-drive firmware for persistence or concealment, a capability that has made the group particularly notable in public malware research. Its tradecraft emphasizes operational security and anti-analysis. Reported techniques include custom string obfuscation, ordinal-only exports, malformed or deceptive API usage, multilayer loaders, manual deployment workflows, kernel drivers, and stealth mechanisms intended to frustrate reverse engineering and automated detection. Some implants have been described as requiring deliberate operator-controlled installation rather than autonomous self-deployment, reflecting a high-touch intrusion model consistent with elite intelligence operations. Equation Group became publicly prominent after the Shadow Brokers leaks, which exposed a large body of offensive tooling widely believed to belong to the actor. Those leaks had major downstream impact because they included exploit capabilities later reused in destructive and criminal campaigns such as WannaCry and NotPetya. Despite the public exposure of some tools, Equation Group remains a benchmark for advanced cyber capability due to its engineering depth, operational discipline, and history of firmware- and kernel-level innovation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sophisticated NSA-associated cyber operation whose offensive tools were allegedly stolen and leaked by Shadow Brokers.
Shadowy hacking operation widely believed to be run by the NSA; its offensive cyber tools were allegedly stolen and leaked by the Shadow Brokers.
The content references Equation Group only as a tag and does not provide substantive details about its activity in the article body.
Associated with the Fast16 cyber sabotage framework, a precision industrial sabotage platform targeting engineering and simulation software by patching floating-point arithmetic routines to subtly alter modeling results.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.