Public research and reverse-engineering efforts exposed the architecture and capabilities of DanderSpritz, the Equation Group post-exploitation framework leaked by the Shadow Brokers. A GitHub documentation project cataloged decompiled Python components and resource files, mapping internal module names to functions including packet capture, memory dumping, keylogging, persistence, credential theft, SQL and Oracle database access, and remote command execution. The material also linked the framework to associated implants and components such as DarkPulsar, DoubleFeature, DoormanGauze, PeddleCheap, and ZippyBang.
Check Point Research later expanded that picture with a deep technical analysis of DoubleFeature, a DanderSpritz logging plugin that revealed how the broader platform handled plugins, command execution, and collection. The researchers described an encrypted log file, a kernel driver named hidsvc.sys loaded via the EpMe exploit for CVE-2017-0005, and rootkit functionality that could invoke kernel APIs through IOCTLs while evading forensic tools. Their work also surfaced forensic artifacts and operational details tied to other Equation Group tools, including UnitedRake, StraitBizarre, KillSuit, DiveBar, FlewAvenue, MistyVeal, DiceDealer, and PeddleCheap.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published a technical analysis of the DoubleFeature plugin within DanderSpritz, detailing its logging architecture, encrypted report handling, and use of the hidsvc.sys driver loaded via the EpMe exploit for CVE-2017-0005. The report also documented indicators and functionality tied to multiple Equation Group tools monitored by DoubleFeature.
A public GitHub repository, DanderSpritz_docs, was published to document and reverse engineer modules from the leaked DanderSpritz framework. The project shared decompiled Python code and resource files from the leak while noting it did not include the full FuzzBunch code, exploits, or runnable binaries.
The Shadow Brokers leaked the Equation Group's DanderSpritz post-exploitation framework as part of the Lost in Translation release. This leak exposed the framework's directory structure, plugins, and components later analyzed by researchers.
Check Point Research states that the Jian exploit was observed in the wild as early as 2014, predating the Shadow Brokers disclosures by about two years. The researchers assess this early use was likely an exception rather than evidence of broad prior access to Equation Group tools.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
epicturla.com
Open sourceresearch.checkpoint.com
Open sourcegithub.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.