DoubleFeature is a Windows diagnostic and logging plugin within the Equation Group’s DanderSpritz post-exploitation framework. It is designed to survey a compromised host and generate an encrypted report describing which Equation Group tools, persistence components, and supporting modules could be deployed or are already present on the target. Rather than serving as an initial access payload, it functions as a post-exploitation assessment utility used after compromise, commonly in environments where DanderSpritz and related implants such as PeddleCheap are already in use.
DoubleFeature departs from DanderSpritz’s standard plugin execution model by preparing a configured DLL that is deployed to the victim and executed to collect host data locally. The component writes an encrypted log for later retrieval and analysis, and its output is intended to be parsed by a dedicated reader utility. Its reporting logic includes checks for multiple Equation Group capabilities and implants, including remote access tools, persistence frameworks, covert networking components, validator implants, and logging parsers.
A notable aspect of DoubleFeature is its use of a kernel driver extracted from embedded resources and loaded through exploitation of CVE-2017-0005. The driver provides privileged functionality to the user-mode component through device control requests, including the ability to invoke selected kernel APIs indirectly. The malware uses several anti-analysis and stealth measures, including encrypted strings, additional obfuscation layers, runtime decryption and re-encryption of data, process-hiding support, and techniques intended to reduce forensic visibility of the driver object.
DoubleFeature is closely associated with the Equation Group and provides insight into the broader DanderSpritz ecosystem, including monitoring for tools such as UnitedRake, StraitBizarre, KillSuit, DiveBar, FlewAvenue, MistyVeal, DiceDealer, and PeddleCheap. Its role is best characterized as reconnaissance and post-exploitation diagnostics inside a mature nation-state intrusion framework targeting Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
we focused our research on a component of DanderSpritz named Doublefeature (or Df for short). According to its own internal documentation, this plugin “Generates a log & report about the types of tools that could be deployed on the target”
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we focused our research on a component of DanderSpritz named Doublefeature (or Df for short). According to its own internal documentation, this plugin “Generates a log & report about the types of tools that could be deployed on the target”
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The rootkit used by DoubleFeature (hidsvc.sys) performs the following actions when it is loaded... It specializes in run-time patching of Windows kernel code.
The strings used in DoubleFeature are decrypted on-demand per function... and they are re-encrypted once function execution completes... DoubleFeature also supports additional obfuscation methods
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A diagnostic utility associated with the Equation Group and used alongside the DanderSpritz malware framework.
A DanderSpritz plugin that inventories and logs other Equation Group tools present on a compromised system, generates encrypted reports, and uses a configured DLL plus a kernel driver to collect extensive victim-side diagnostic data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.