SYMBOLCOMMON_NAMEaka. SYNONYMS

Equation Group  (Back to overview)

aka: EQGRP, G0020, Tilded Team

The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups in the world, operating alongside but always from a position of superiority with the creators of Stuxnet and Flame


Associated Families
elf.bvp47 elf.doublefantasy win.darkpulsar win.doublefantasy win.doublepulsar win.equationdrug win.fancyfilter win.fanny win.grok win.mistyveal win.oddjob win.peddlecheap win.tildeb

References
2022-05-11ExaTrackTristan Pourcelot
Tricephalic Hellkeeper: a tale of a passive backdoor
BPFDoor Bvp47 Uroburos
2022-04-11Pangu LabPangu Lab
Bvp47 Technical Details Report II
Bvp47
2022-02-23The Hacker NewsRavie Lakshmanan
Chinese Experts Uncover Details of Equation Group's Bvp47 Covert Hacking Tool
Bvp47
2022-02-23Pangu LabPangu Lab
The Bvp47 - a Top-tier Backdoor of US NSA Equation Group
Bvp47
2022-02-23Bleeping ComputerIonut Ilascu
NSA-linked Bvp47 Linux backdoor widely undetected for 10 years
Bvp47
2022-02-22Pangu LabPangu Lab
Bvp47 - Top-tier Backdoor of US NSA Equation Group
Bvp47
2021-12-27Checkpoint Research
A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
Equationgroup (Sorting) Fanny MISTYVEAL PeddleCheap
2021-12-01ESET ResearchAlexis Dorais-Joncas, Facundo Muñoz
Jumping the air gap: 15 years of nation‑state effort
Agent.BTZ Fanny Flame Gauss PlugX Ramsay Retro Stuxnet USBCulprit USBferry
2021-06-10ESET ResearchAdam Burgher
BackdoorDiplomacy: Upgrading from Quarian to Turian
CHINACHOPPER DoublePulsar EternalRocks turian BackdoorDiplomacy
2021-02-05EpicTurlaJuan Andrés Guerrero-Saade
Voltron STA The curious case of 0xFancyFilter
fancyfilter MISTYVEAL Regin
2020-09-28fmmresearch wordpressFacundo Muñoz
The Emerald Connection: EquationGroup collaboration with Stuxnet
Fanny Stuxnet
2020-09-28fmmresearch wordpressFacundo Muñoz
The Emerald Connection: Equation Group collaboration with Stuxnet
Fanny Stuxnet
2020-09-10Kaspersky LabsGReAT
An overview of targeted attacks and APTs on Linux
Cloud Snooper Dacls DoubleFantasy MESSAGETAP Penquin Turla Tsunami elf.wellmess X-Agent
2020-08-27fmnagisa wordpressFacundo M
Revisiting EquationGroup’s FANNY… or is it DEMENTIAWHEEL?
DoubleFantasy Fanny
2020-08-15Twitter (@Int2e_)Adrien B
Tweet on DoubleFantasy
DoubleFantasy
2020-05-07Twitter (@ESETresearch)ESET Research
Tweet on PeddleCheap packed with Winnti packer
PeddleCheap
2020-01-01SecureworksSecureWorks
PLATINUM TERMINAL
TalentRAT Equation Group Longhorn
2019-11-08WikipediaVarious
Wikipedia Entry on Equation Group
Equation Group
2019-05-07SymantecSecurity Response Attack Investigation Team
Buckeye: Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
DoublePulsar
2019-01-01Council on Foreign RelationsCyber Operations Tracker
Equation Group
Equation Group
2019-01-01MITREMITRE ATT&CK
Group description: Equation
Equation Group
2018-12-13Trend MicroMohamad Mokbel
Tildeb: An Implant from the Shadow Brokers’ Leak
tildeb
2018-02-06ForcepointJohn Bergbom
DanderSpritz/PeddleCheap traffic analysis (Part 1 of 2)
PeddleCheap
2017-11-13Obscurity LabsObscurity Labs
Match Made In The Shadows: Part [3]
PeddleCheap
2017-03-30Artem Baranov
EquationDrug rootkit analysis (mstcp32.sys)
EquationDrug
2016-11-04Antiy CERTAntiy CERT
FROM EQUATION TO EQUATIONS
DoubleFantasy
2016-10-05ThaiCERT
The Shadow Brokers auctions cyber weapons from Equation Group
Equation Group
2015-03-11Kaspersky LabsGReAT
Inside the EquationDrug Espionage Platform
EquationDrug
2015-02-16Kaspersky LabsGReAT
Equation: The Death Star of Malware Galaxy
DoubleFantasy EquationDrug Fanny GROK
2015-02-16Ars TechnicaDan Goodin
How “omnipotent” hackers tied to NSA hid for 14 years—and were found at last
Equation Group
2015-02-16Kaspersky LabsGReAT
Equation: The Death Star of Malware Galaxy
Fanny
2015-02-01Kaspersky LabsKaspersky
Equation Group: Questions and Answers
Equation Group
2014-04-17Nettitude LabsNettitude Labs
A quick analysis of the latest Shadow Brokers dump
DarkPulsar
2010-09-01WikipediaWikipedia
Stuxnet
Equation Group

Credits: MISP Project