DoubleFantasy is an Equation Group implant used as an early-stage validation and reconnaissance component in targeted intrusion operations. It is associated with the broader Equation malware ecosystem alongside platforms such as EquationDrug, GrayFish, and Fanny, and has been described as a lightweight foothold used to profile victims, collect credentials and system information, and provide generic remote access before deployment of more fully featured tooling.
DoubleFantasy has been documented on multiple operating systems, including Windows, Linux, Solaris, and macOS, indicating a cross-platform operational capability uncommon outside highly resourced espionage actors. On Linux, it has been observed gathering host profiling data such as operating system and kernel details, platform characteristics, uptime, language, network configuration, and user information, while also collecting account and password data, clearing login records, and communicating with command infrastructure for tasking. Analysis of Linux samples indicates anti-debugging behavior, encrypted internal strings, and custom encrypted communications consistent with the Equation toolchain. Solaris-related reporting describes both a DoubleFantasy component and supporting rootkit functionality used for daemonization, command execution, file operations, configuration updates, and collection of host and process information, including access to account password data. macOS reporting identifies DoubleFantasy as one of the notable government-grade implants analyzed for that platform.
Within the Equation ecosystem, DoubleFantasy is closely tied to staged post-compromise operations. It has been characterized as a target-screening implant that can exfiltrate collected data, relay commands, and download or hand off to more capable follow-on malware. Windows-related analysis also links DoubleFantasy to the distinctive Equation cryptographic implementation seen across leaked and previously documented tooling, reinforcing its placement within that espionage framework.
DoubleFantasy is best understood as a modular espionage backdoor used for victim validation, credential collection, reconnaissance, and controlled follow-on access in high-end intelligence operations rather than as a mass-distributed commodity threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We have captured the samples on Linux platform and confirmed that the sample is DoubleFantasy component after analyzing. The component is used to perform incipient detection on targets with Linux platform.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
These components act as Rootkits... This is a rootkit program on the Solaris platform of the SPARC architecture. It is primarily responsible for hiding the main function sample files like other rootkit programs, as well as the associated derived files and itself, including process, file, and service information.
The function and data called by this sample is dynamically loaded and debugged... We explain the calling addresses through dynamic analysis decryption.
After running, it can combine two sets of strings... to generate file name as its own new file name, and copy itself to the / sbin / directory... these words are highly frequency words or suffix used in system files and system command.
Traversing system files, clearing / var / log / lastlog records... 0x42 Clear traces of infection, delete itself.
If the parameter '-c' engages in, only system information can be obtained and it can be regarded as scene detection... Collecting information about infected computers, including system directory, file extension, and other information.
Many encryption algorithms used in communication and information... Network communication encryption... This sub key is used for encrypting and decrypting to send and receive data.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A US government macOS implant, analyzed in 2021, used for espionage and persistent access.
Early-stage Linux implant from the Equation group that collects system information and credentials and provides generic access to infected systems.
Equation Group malware/toolset cited in the article; a sample (actxprxy32.dll) is specifically referenced for its encryption-related code implementing the rare RC5/RC6 routine.
Referenced as the basis for one EquationDrug C2 communication plugin using the WinInet API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.