DoublePulsar is a Windows backdoor/implant widely associated with the NSA offensive toolset later leaked by the Shadow Brokers. The content describes it as a persistent backdoor used to access previously compromised systems and execute additional code, and notes that it waits for specially crafted traffic over SMB on TCP port 445 and returns a distinctive response that can be used for detection. Multiple sources in the content also describe it as highly stealthy because it writes no files to disk and is removed on reboot.
DoublePulsar is closely tied to SMB exploitation chains involving MS17-010-era tooling, especially EternalBlue, and is described as shellcode executed after successful exploitation of vulnerable Windows systems. The content states that EternalBlue was used to remotely install DoublePulsar, and that exploit chains including EternalBlue and DoublePulsar were later reused broadly by other actors.
The malware was used prominently in WannaCry/WCry/WanaCry propagation, where the ransomware checked for or implanted DoublePulsar and then used it to install and execute the ransomware payload on compromised hosts. The content also states that NotPetya reused EternalBlue and DoublePulsar. Additional observed use includes a staged Blackmoon/KRBanker campaign in which a spreader dropped DoublePulsar and EternalBlue components to move laterally, and a Satan ransomware variant that used DoublePulsar to load a DLL into memory and execute a downloader on remote machines.
The content links DoublePulsar to multiple threat actors and operations. BackdoorDiplomacy is explicitly said to have obtained and used leaked malware including DoublePulsar. Symantec reporting cited in the content states that Buckeye/APT3/Gothic Panda/UPS Team/TG-0110 used a variant of the NSA-developed DoublePulsar backdoor as early as March 2016, before the public Shadow Brokers leak. More recent telemetry in the content also places DoublePulsar in exploit chains relied on by Sandworm/APT44/Seashell Blizzard/Voodoo Bear in intrusions affecting industrial and OT environments.
Targeting reflected in the content is broad and opportunistic where DoublePulsar is used as part of wormable SMB exploitation, but reported victim sectors include telecommunications providers, research organizations, educational institutions, major telecommunications networks, and industrial/OT environments. High-confidence behavioral details directly mentioned in the content include listening for specific SMB traffic on port 445, providing a distinctive network response, enabling remote code execution or payload delivery on compromised systems, and being used as a delivery mechanism for follow-on malware such as ransomware and in-memory DLL payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft addressed the SMBv1 vulnerabilities in March 2017 with Security Bulletin MS17-010. The worm specifically scans for the existence of the DoublePulsar backdoor on compromised systems. If the DoublePulsar backdoor does not exist, then the SMB worm attempts to compromise the target using the Eternalblue SMBv1 exploit.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
The worm specifically scans for the existence of the DoublePulsar backdoor on compromised systems.
Symantec discovered that as early as March 2016, the Chinese hackers were using tweaked versions of two N.S.A. tools, called Eternal Synergy and Double Pulsar, in their attacks.
Symantec reported that two of those advanced hacking tools were used against a host of targets starting in March 2016... an advanced persistent threat hacking group... somehow got access to a variant of the NSA-developed “DoublePulsar” backdoor and one of the Windows exploits the NSA used to remotely install it on targeted computers.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
The fake HandlerFunction is executed, but this function is the shellcode.
The infection of other machines on the network will be achieved with the following command: cmd /c cd /D C:\Users\Alluse~1\&blue.exe ...
As Ars reported last week, the ultra-stealthy DoublePulsar writes no files to the hard drives of computers it infects, a feature that causes it to be removed as soon as the computer restarts.
Researcher Kevin Beaumont told Ars that detecting DoublePulsar involves sending a series of SMB—short for server message block—queries to Internet-facing computers.
In essence, the transport code scanned the network for vulnerable computers, then used the EternalBlue exploit to access them by sending crafted packets from attackers, allowing them to execute arbitrary code remotely. | The references include WannaCry-related material such as “CVE-2017-0143,” “DoublePulsar Explained,” and “SMB Exploited: WannaCry Use of ‘EternalBlue.’”
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A well-known kernel implant referenced as design inspiration for NebulaPulsar’s resident implant model.
Backdoor implant referenced as part of exploit chains used in pre-compromised environments that Sandworm later leveraged to move deeper into industrial networks.
Backdoor component appearing in exploit chains that Sandworm capitalized on in already-compromised environments.
Referenced as an example of a real-world implant used alongside exploitation techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.