DarkPulsar is a Windows kernel backdoor associated with the Equation Group toolset exposed through the Shadow Brokers leaks. It is commonly described as an implant within the broader DanderSpritz ecosystem and has been characterized as a legacy implant older than PeddleCheap. Public reporting has also described it as a kernel-resident backdoor that can be paired with the EternalBlue SMB exploit to establish covert access on compromised systems.
As a kernel-level implant, DarkPulsar is designed for post-exploitation access and stealthy persistence within the trusted core of a Windows system. Reporting on the leaked NSA tooling indicates it functioned as a backdoor implant rather than a standalone initial-access exploit, enabling operators to maintain control after compromise. Its association with other Equation Group components places it in a mature offensive framework used for follow-on operations after exploitation.
DarkPulsar is most strongly linked to Windows environments and to state-grade intrusion activity attributed by multiple researchers to the Equation Group. It became widely known after the Shadow Brokers disclosures, particularly in discussions of chained use with EternalBlue against unpatched SMB vulnerabilities. High-confidence public descriptions support classifying it as a backdoor implant for Windows used in post-compromise operations, with an emphasis on stealth and kernel-level residence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other implants have names such as Darkpulsar-1.1.0.exe, Mofconfig-1.0.0.exe, and PluginHelper.py.
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kernel-level backdoor used to maintain stealthy access by operating deep in the OS core, often paired with EternalBlue-enabled compromise.
Referenced as an implant included in the leaked toolset; specific functionality is not described in the provided content.
Named in the leak as an implant component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.