Internet-wide scans found the NSA-linked DoublePulsar SMB backdoor on tens of thousands of exposed Windows systems after Shadow Brokers released offensive tooling tied to the implant. Researchers reported infection estimates ranging from roughly 30,000 to more than 120,000 hosts, with infected machines responding to distinctive traffic over port 445; Microsoft questioned the early counts, but independent investigators said the backdoor had spread rapidly and Countercept later published a method to remotely remove it. Because DoublePulsar operates in memory and leaves no files on disk, it was described as unusually stealthy even as defenders raced to identify and clean compromised systems.
Subsequent reporting showed the impact of the leak extended well beyond the initial infections. Symantec said a China-linked group known as Buckeye/APT3 had used a DoublePulsar variant and related NSA exploit code in real-world attacks as early as March 2016, indicating the capabilities were exposed or replicated long before the public dump. Other leaked SMB exploits, including EternalChampion, EternalRomance, and EternalSynergy, were later ported to work across Windows versions from 2000 through modern releases, while related Shadow Brokers tools such as EternalBlue were tied to major outbreaks including WannaCry and NotPetya, reinforcing the urgency of applying Microsoft’s MS17-010 patches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
In May 2019, Symantec disclosed that Buckeye had used a DoublePulsar variant and related exploit beginning in March 2016, suggesting NSA cyber capabilities had been exposed, copied, or stolen far earlier than previously understood.
By November 2018, reporting highlighted that about 45,000 systems remained vulnerable or exposed to older NSA-linked Windows exploitation techniques, underscoring persistent patching failures long after the original leaks.
In March 2018, reporting on leaked NSA files showed that the agency had developed Territorial Dispute scripts that, by 2013, were being used to identify other nation-state and advanced threat actors on compromised machines using a compact set of signatures.
RiskSense researcher Sean Dillon adapted EternalChampion, EternalRomance, and EternalSynergy to work across a broad range of Windows versions from Windows 2000 through modern Windows 10 and Server 2016 builds, and the code was merged into Metasploit. Patched systems protected by MS17-010 were not affected.
In May 2017, following the global WannaCry outbreak tied to leaked NSA SMB tooling, the Shadow Brokers publicly threatened to release more hacking tools and exploits.
By late April 2017, independent scans were estimating roughly 30,000 to more than 120,000 infected systems, and Countercept published an updated detection script capable of remotely uninstalling DoublePulsar from affected hosts.
Soon after the leak, security researchers reported active exploitation of exposed Windows hosts and identified tens of thousands of systems that appeared to be infected with the DoublePulsar backdoor over SMB port 445. Microsoft said it doubted the reported totals and was investigating.
In April 2017, the Shadow Brokers publicly released NSA offensive tools including SMB exploits and the DoublePulsar implant, making the capabilities broadly available to attackers and defenders.
Symantec later reported that the Buckeye/APT3 group used a variant of the NSA-developed DoublePulsar backdoor and a related Windows exploit against multiple targets beginning in March 2016, indicating the capability was in use well before the public Shadow Brokers leak.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcetheintercept.com
Open sourcebleepingcomputer.com
Open sourcetheguardian.com
Open sourcearstechnica.com
Open sourcearstechnica.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.