EquationLaser is an early malware platform associated with the Equation Group, a highly sophisticated cyberespionage actor known for long-running computer network exploitation operations. It is identified as one of the group’s core toolsets and predates EquationDrug, which replaced it before later being superseded by GrayFish. Publicly available reporting places EquationLaser within a broader lineage of modular Equation Group implants used for selective, victim-specific intrusions rather than indiscriminate mass deployment.
High-confidence information about EquationLaser’s internal architecture and feature set is limited in the available material. Its inclusion alongside other Equation Group platforms indicates it formed part of a mature espionage arsenal used against carefully chosen targets. The surrounding tool ecosystem used by the same actor is notable for stealth, persistence, modular expansion, and intelligence collection, but specific capabilities should not be attributed to EquationLaser without direct corroboration.
EquationLaser is primarily associated with Windows-focused Equation Group operations. It is best understood as an earlier-generation Equation Group implant/platform in the evolutionary chain that led to the more extensively documented EquationDrug and GrayFish frameworks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It’s been in use for over 10 years, replacing EquationLaser until it was replaced itself by the even more sophisticated GrayFish platform.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Equation group implant named as part of the group's malware arsenal.
An earlier Equation Group espionage platform that was replaced by EquationDrug.
An earlier Equation Group espionage platform that was replaced by EquationDrug.
An early implant from Equation Group used around 2001-2003 and compatible with Windows 95/98.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.