Fanny is an Equation Group worm. The provided content states it was an earlier Equation Group malware family and toolset referenced alongside EQUATIONDRUG, DOUBLEFANTASY, and GRAYFISH. It is notable for its technical connection to Stuxnet: researchers cited in the content state that Fanny used two Stuxnet zero-days one to two years before Stuxnet appeared, including the Windows LNK exploit CVE-2010-2568 and another privilege-escalation exploit embedded in Stuxnet’s Resource 207. This exploit sharing was described as a key link between Equation Group activity and Stuxnet, and researchers also noted shared coding practices between Stuxnet and Equation developers. The content does not provide a fuller behavioral profile for Fanny beyond identifying it as a worm and linking it to Equation Group operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Equation, on the other hand, would eventually be connected by the use of exploits shared by both Stuxnet and an earlier Equation Group worm named Fanny.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Having originally uncovered the Equation group in February 2015, we’ve taken a look at the newly released files to check for any connections with the known toolsets used by Equation, such as EQUATIONDRUG, DOUBLEFANTASY, GRAYFISH and FANNY.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm referenced for its exploits, which were later tied into the broader connections among Stuxnet, Duqu, and the Equation group.
An Equation Group worm said to have used two Stuxnet zero-days one to two years before Stuxnet, helping connect Equation to the broader malware cluster discussed.
An Equation Group worm that used two Stuxnet zero-days 1–2 years before Stuxnet appeared, helping connect Equation to the broader collaborative cluster discussed in the article.
Equation Group malware referenced among known toolsets used for technical comparison with the ShadowBrokers dump, especially around a distinctive RC5/RC6 implementation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.