Researchers reported that the Equation Group operated a highly modular espionage platform across Windows, Linux, and Solaris/SPARC, extending the reach of its long-running EquationDrug toolset beyond previously documented Windows infections. Analysis identified a Linux x86 DoubleFantasy implant used for target validation and reconnaissance, alongside Solaris SPARC components including a rootkit and a Solaris DoubleFantasy module for persistence, host profiling, concealment, and remote command execution. The Solaris malware was described as capable of hiding files, processes, and services, installing startup scripts, generating hidden directories from host-specific values, and decrypting embedded payloads for execution.
The findings tie the non-Windows implants to the broader EquationDrug ecosystem through shared custom encryption logic and the same 16-byte key material previously associated with Windows DoubleFantasy communications and registry encryption. Separate analysis of EquationDrug described a mature espionage framework with kernel- and user-mode components, encrypted storage, plugin-based extensibility, process injection, audit-log suppression, passive network backdoors, and capabilities including file theft, screenshots, keylogging, browser monitoring, removable-media surveillance, and even HDD/SSD firmware manipulation. Investigators also linked the Solaris tooling to command-and-control infrastructure, including the domain xxxech.com and an IP address in the same subnet as Windows-related infrastructure, reinforcing the assessment that Equation Group maintained a sophisticated, multi-platform cyberespionage capability.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In November 2016, Antiy published a report analyzing Equation Group malware for Linux and Solaris/SPARC, arguing it demonstrated multi-platform capability beyond Windows. The report said this was the first proof of Equation malware on those platforms and linked the Linux and Solaris samples to previously known Windows DoubleFantasy encryption material and infrastructure.
On March 12, 2015, Securelist published a detailed analysis of the EquationDrug espionage platform, describing its modular architecture, stealth features, and long-running use by the Equation Group.
Securelist says EquationDrug dates back to 2003 and became one of the Equation Group's main espionage platforms, replacing the earlier EquationLaser framework.
Securelist reports that Equation Group operations date back to 2001, establishing a confirmed early period for the threat actor's activity.
Kaspersky's analysis states the Equation Group's computer network exploitation activity may date back to 1996, indicating very early development of the actor's capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.