Skip to main content
Mallory
2 malware families

ShadowBrokers

Also known asshadowbrokers

Shadow Brokers is the name used by an entity that emerged publicly on 2016-08-13 claiming to possess files belonging to the Equation Group. The group released multiple dumps, including a free archive of roughly 300 MB containing firewall exploits, tools, and scripts, while another encrypted archive was offered separately. Reporting in the provided content states that the leaked material included tools and documentation allegedly stolen from the Equation Group and later releases allegedly included targeting of SWIFT service bureaus. The content does not provide high-confidence attribution of Shadow Brokers to any specific country or sponsor. However, multiple sources in the content describe strong technical linkage between the leaked tools and the Equation Group rather than proving who Shadow Brokers themselves were. Kaspersky assessed with high confidence that the leaked tools were related to the Equation Group, based in part on a rare RC5/RC6 implementation seen across hundreds of leaked files and previously observed in Equation malware. A separate analysis in the content disputes the strength of one specific RC6-based authorship argument, noting that the subtraction form of the RC6 constant on x86 can be compiler-generated and is therefore not conclusive by itself. Shadow Brokers is notable in the content primarily as a leak actor or persona rather than as an operator described conducting intrusions directly. The leaked archive exposed numerous Equation-associated tools and cryptonyms, including BANANAUSURPER, BLATSTING, BUZZDIRECTION, BANANAGLEE, and material later referenced in relation to EQUATIONVECTOR, identified in Shadow Brokers disclosures as "PeddleCheap." The name "fast16" also appeared in a document leaked by Shadow Brokers concerning NSA offensive cyber weapons. Known alias in the provided content: shadowbrokers.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0008
Lateral Movement
1 technique
T1210
Exploitation of Remote Services
TA0009
Collection
1 technique
T1213
Data from Information Repositories
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.

ShadowBrokers | Mallory