Kaspersky reported that the tools released by ShadowBrokers bear strong technical hallmarks of the Equation Group, tying the leaked firewall exploits, scripts, and operational tooling to one of the most sophisticated known cyber-espionage arsenals. The strongest evidence came from a rare RC5/RC6 cryptographic implementation previously seen only in Equation malware, including the unusual use of the constant 0x61C88647 in a subtraction-based routine.
Researchers found 347 RC5/RC6 instances in the leaked archive, with more than 300 files using that specific RC6 variant across 24 forms, reinforcing the attribution with high confidence. The free archive released by ShadowBrokers contained roughly 300MB of material, mostly timestamped from August to October 2013, and some researchers said they were able to successfully test certain exploits, indicating that at least part of the leaked toolkit was operational and authentic.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Shadow Brokers published a new tranche of offensive cyber tools and implants, including Oddjob, Darkpulsar, Mofconfig, and PluginHelper. Researchers said the leak included evidence of targeting against Al Quds Bank for Development and Investment, and many of the implants were initially largely undetected by antivirus products.
Kaspersky analyzed the August 2016 leak and found strong technical evidence connecting the leaked tools to the Equation Group. The researchers identified a rare RC5/RC6 implementation previously seen only in Equation malware, including the unusual constant 0x61C88647, and concluded with high confidence that the leaked materials were related to the group.
A free archive of roughly 300MB containing firewall exploits, tools, and scripts was leaked by the ShadowBrokers. The files carried timestamps mostly from August to October 2013, and some researchers reported that certain exploits worked in testing.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcearstechnica.com
Open sourcetheregister.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.