DanderSpritz is a full-featured post-exploitation framework associated with the Equation Group and exposed publicly through the Shadow Brokers leak. It is designed for use after initial compromise and commonly operates in conjunction with implants such as PeddleCheap, providing operators with a modular environment for tasking, collection, diagnostics, persistence support, and follow-on tooling deployment on compromised Windows systems.
The framework uses a plugin-based architecture in which commands are mapped to scripts and components through XML-defined aliases and resources. Documented modules and related components indicate broad post-compromise functionality, including keylogging, memory dumping, packet capture, command execution, SQL and Oracle database interaction, credential theft, environment survey, and collection of host and network data. Associated tooling includes implants and utilities such as DarkPulsar, DoubleFeature, DoormanGauze, PeddleCheap, ZippyBang, GreaterSurgeon, Strangeland, and PassFreely.
DoubleFeature, one of the better-characterized DanderSpritz components, functions as a diagnostic and logging plugin used to identify or assess other Equation Group tools present on a target. Its implementation demonstrates the framework’s ability to generate and deploy specialized DLL-based components, retrieve encrypted reports, and leverage kernel-mode support. Analysis of DoubleFeature shows use of an embedded driver loaded via exploitation of CVE-2017-0005, rootkit-style stealth, runtime string and code obfuscation, and kernel API invocation through device control requests. The same analysis links DanderSpritz to a wider ecosystem of Equation Group capabilities, including persistence and evasion frameworks, covert networking components, validator implants, and exfiltration-oriented tooling.
DanderSpritz is best understood as an operator console and orchestration framework rather than a single standalone implant. Its role is to manage post-exploitation activity on victim systems, especially Windows hosts, after access has already been established. The framework’s documented modules suggest targeting flexibility across enterprise environments and support for long-term clandestine operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The goal of this project is to document the different capabilities and functionality of the DanderSpirtz post-exploitation framework / application by examining the contents of the "resources" folder included in the ShadowBrokers leak...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of an offensive security tool that supports plugins.
A malware framework associated with the Equation Group, mentioned as being used together with DoubleFeature.
A modular post-exploitation framework used after initial compromise, containing tools for persistence, reconnaissance, lateral movement, antivirus bypass, and management of victim-side components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.