Researchers disclosed new technical details on Bvp47, a stealthy Linux backdoor attributed to the Equation Group, after matching the malware’s RSA private key and framework components to material exposed in the Shadow Brokers leak. Pangu Lab said it originally recovered the implant during a 2013 forensic investigation into an intrusion it called Operation Telescreen, where attackers compromised internal servers and used an external relay host to pass commands, move payloads, and exfiltrate encrypted data. The malware used covert command-and-control over TCP SYN packets, obfuscation, and self-destruction features that helped it evade detection for more than a decade.
The disclosure adds to a broader body of reporting on the Equation Group as one of the most advanced cyber-espionage operators observed, with Kaspersky previously linking the actor to a large arsenal of implants, firmware-level persistence, USB-based operations against air-gapped networks, and overlap with the Stuxnet and Flame ecosystems. Reporting on the Shadow Brokers dump also showed the group’s tooling included Windows exploitation frameworks, SMB-focused capabilities, and PowerShell-based payload delivery, while code-level similarities between Bvp47 and other Equation-linked malware further reinforced the attribution. Pangu said Bvp47 was used against more than 287 organizations in 45 countries, including targets in telecom, military, education, economic, and scientific sectors.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
Reporting on Pangu's disclosure said Kaspersky found code-level similarities between Bvp47 and an Equation-related Solaris sample, reinforcing the attribution to the Equation Group.
Pangu Lab publicly disclosed the covert Linux backdoor Bvp47, describing its TCP SYN covert channel, stealth features, and use against more than 287 targets in 45 countries, and attributed it to the Equation Group using overlaps with Shadow Brokers materials including the implant's RSA private key.
The Hacker News said Check Point Research disclosed another previously undocumented Equation Group utility named DoubleFeature in late December 2021.
Securelist published research linking Black, White, Blue, Green, Pink, and Gray Lambert through shared code, infrastructure, and victim overlap, outlining the toolkit's evolution.
Nettitude analyzed a Shadow Brokers dump released in April 2017 that exposed alleged NSA Equation Group Windows exploits and tooling including ZiPo and DAMAGEDGOODS.
Securelist said migration from White Lambert to Gray Lambert was still being seen in 2016, marking the latest known activity discussed for the toolkit.
Shadow Brokers leaked Equation Group exploit tools and related materials, later used by researchers to compare and attribute additional malware families.
Kaspersky Lab's GReAT announced discovery of the Equation Group, describing its advanced implant arsenal, hard-drive firmware persistence, air-gap tradecraft, and links to Stuxnet and Flame.
Securelist said FireEye publicly uncovered in October 2014 an in-the-wild attack using zero-day CVE-2014-4148, and Microsoft patched the flaw at disclosure time.
Securelist reported that an OS X variant of Green Lambert with codename HO BO and version 1.2.0 was uploaded to a multiscanner service from Russia in September 2014.
A high-profile organization in Europe was attacked in 2014 with Black Lambert using the Windows TrueType Font zero-day CVE-2014-4148.
BleepingComputer reported that a Bvp47 sample was first submitted to VirusTotal in late 2013 and initially drew detection from only one antivirus engine.
Nettitude's analysis of the Shadow Brokers dump said metadata on makedmgd.exe indicated a build date in July 2013, suggesting the leaked DAMAGEDGOODS tooling dated from that period if untampered.
Pangu Lab said it extracted the Bvp47 Linux backdoor during a forensic investigation of a host in a key domestic department, identifying an intrusion later codenamed Operation Telescreen.
Kaspersky reported that in 2008 the Equation Group's Fanny worm mapped air-gapped networks using a USB-based command-and-control mechanism and used two zero-days later seen in Stuxnet.
Securelist said the Lamberts, also known as Longhorn, had used sophisticated malware against high-profile victims since at least 2008 across Windows and OS X environments.
Kaspersky reported that the Equation Group had infected thousands to tens of thousands of victims across more than 30 countries since 2001, affecting government, telecom, aerospace, energy, military, finance, and other sectors.
After Pangu's report circulated in the infosec community, BleepingComputer said VirusTotal detections for the Bvp47 sample increased from one engine to six.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourcelabs.nettitude.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.