Equation Group is a highly sophisticated, state-sponsored cyber espionage threat actor widely believed to be associated with the U.S. National Security Agency. Reporting in the provided content describes it as one of the most advanced hacking operations observed, with computer network exploitation activity dating back to at least 2001 and possibly as early as 1996. Known aliases and related naming in the content include Equation Group and the NSA’s Tailored Access Operations (TAO) group; Chinese investigators are noted as referring to TAO as APT-C-40. The content describes Equation Group as operating long-running, modular espionage platforms including EquationDrug, which Kaspersky characterized as a primary framework later superseded by GrayFish. EquationDrug is described as a plugin-based platform with kernel- and user-mode components, encrypted virtual file system storage, and extensive surveillance capabilities including file theft, screenshots, network interception, browser monitoring, keylogging, removable media monitoring, NTFS forensics, passive network backdoors, and HDD/SSD firmware manipulation. Supporting components named in the content include msndsrv.sys, mscfg32.exe, mscfg32.dll, tdip.sys, mstcp32.sys, msrtvd.sys, volrec.sys, and nls_933w.dll. The actor is specifically linked in the content to deep persistence and firmware-level capabilities. Multiple references describe an HDD reprogramming or firmware manipulation capability, including the nls_933w.dll / WIN32M.sys component and the EquationDrug plugin nls933w.dll. Analysis cited in the content states that nls_933w.dll embeds a kernel driver, communicates with it via custom IOCTLs, issues ATA IDENTIFY DEVICE commands, checks drive vendor strings such as SAMSUNG, ST, Maxtor, and WDC WD, and appears intended for stealthy manual deployment rather than automatic self-loading. The same reporting describes anti-analysis and anti-virus evasion features including ordinal-only exports, custom XOR string obfuscation, malformed API parameters, and intentionally invalid path construction to prevent automatic release of the embedded driver to disk. The content also associates Equation Group with passive backdoor capability, citing implants such as Bvp47 and DewDrop, and notes code and tooling overlap with material later leaked by the Shadow Brokers. Multiple sources in the content state that Shadow Brokers tools bore unique signatures tied to Equation Group and were widely assessed as genuine NSA-origin offensive tooling. Leaked tools and projects referenced in the content include SecondDate, BANANAGLEE, and FAST16. Targets are described broadly as espionage victims and high-value networks. The content notes Equation Group malware found alongside other nation-state toolsets on a Middle Eastern research institute system, and broader reporting ties the actor to advanced surveillance and covert access operations rather than financially motivated crime. Overall, the provided material portrays Equation Group as a U.S. nation-state espionage actor with mature modular tooling, kernel and firmware expertise, stealth-focused deployment, and exceptionally advanced persistence and anti-analysis tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.