DoublePulsar is a Windows kernel-mode backdoor and volatile implant associated with the Equation Group toolset leaked by the Shadow Brokers in 2017. It is commonly deployed following remote exploitation of vulnerable SMB services, notably through EternalBlue, and supports communications over SMB or RDP. The implant hooks an SMB transaction handler and interprets specially formed requests as operator commands. Supported functionality includes host probing, in-memory DLL injection into specified user-mode processes, shellcode execution, and removal of the implant. DoublePulsar can use kernel-assisted APC mechanisms to inject payloads into user-mode processes and is designed to operate without a persistent on-disk component; rebooting removes it from memory. It was extensively abused in 2017 by WannaCry-related propagation and has subsequently been reused by multiple criminal and state-linked intrusion operations, including activity attributed to BackdoorDiplomacy. Its kernel-level operation and in-memory payload execution complicate endpoint detection and can enable follow-on remote code execution on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Volatile kernel mode implant • Loaded via remote ring0 exploit (ex ETERNALBLUE) • Evade PatchGuard ... • Injects DLLs into usermode via APCs
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
the ransomware perpetrators used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMBv1 server. This vulnerability was fixed in security bulletin MS17-010
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
approximately 15 000 systems have been observed to be compromised with "DoublePulsar" ... The number of compromised hosts with “DoublePulsar” installed is now reported to be more than 200 000 machines.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
Symantec reported that two of those advanced hacking tools were used against a host of targets starting in March 2016... an advanced persistent threat hacking group... somehow got access to a variant of the NSA-developed “DoublePulsar” backdoor and one of the Windows exploits the NSA used to remotely install it on targeted computers.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
During our analysis, we also discovered that Amadey was actively pushing the Remcos RAT via its control panel... We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine.
Once DoublePulsar is installed, a PowerShell command is executed, and contact is made with the Beapy command and control (C&C) server, before a coinminer is downloaded onto the target computer.
Once on a victim's machine, Amadey sends user data to a Command and Control (C&C) server and executes other tasks sent back by the C&C server.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor opened via EternalBlue and used in the WannaCry intrusion chain to locate accessible targets and deliver ransomware.
Kernel-level backdoor/implant from the leaked Shadow Brokers dump, reachable via port-knocking over RDP/SMB and described as difficult to detect. It is also installed post-exploitation by WannaCry before the ransomware component is loaded.
A well-known kernel implant referenced as design inspiration for NebulaPulsar’s resident implant model.
Backdoor implant referenced as part of exploit chains used in pre-compromised environments that Sandworm later leveraged to move deeper into industrial networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.