Equation
Also reported as Equation Group, Tilded Team, EQGRP, Platinum Colony and APT-C-40. Linked to United States by three sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2006-3439
- CVE-2006-6493
- CVE-2008-4250 KEV
- CVE-2010-0232 KEV
- CVE-2010-2568 KEV
- CVE-2010-2729
- CVE-2010-2743
- CVE-2010-2772
- CVE-2010-3338
- CVE-2010-3888
- CVE-2010-3962 KEV
- CVE-2010-4398 KEV
Show all 84 CVEs Show fewer
- CVE-2011-1255
- CVE-2011-3402 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0159
- CVE-2012-1723 KEV ransomware
- CVE-2012-3015
- CVE-2012-4681 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-3128
- CVE-2013-3893 KEV
- CVE-2013-3894
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4148 KEV
- CVE-2014-6287 KEV
- CVE-2014-6324 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2015-0096
- CVE-2015-0097
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2360 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0165 KEV
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-3393 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0005 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0145 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-8464 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9791 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-1000861 KEV
- CVE-2018-20062 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-8345
- CVE-2018-8346
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0703 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-1188
- CVE-2019-1280
- CVE-2019-18935 KEV ransomware
- CVE-2019-9081
- CVE-2020-0601 KEV
- CVE-2020-0684
- CVE-2020-0729
- CVE-2020-1299
- CVE-2020-1421
- CVE-2020-5902 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Flame (malware)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DoublePulsar
-
Equation Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Equation Group - Threat Group Cards: A Threat Actor Encyclopedia
-
202304114e0fa0f4fd1d408aaddeef8be63a4757_20230411161526_0531.pdf
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor 202304114e0fa0f4fd1d408aaddeef8be63a4757_20230411161526_0531.pdf
Show all 111 reports Show fewer
-
A Fanny Equation - I am your father Stuxnet.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Fanny Equation - I am your father Stuxnet.pdf
-
The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group_ii.en.pdf
The original link failed its last check. Original publisher Detailsfor The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group_ii.en.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Quantum Attack System – NSA -APT-C-40- Hacking Organization High-end Cyber Attack Weapon Technical Analysis Report (I)
-
NSA-linked Bvp47 Linux backdoor widely undetected for 10 years
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NSA-linked Bvp47 Linux backdoor widely undetected for 10 years
-
The Bvp47 - a Top-tier Backdoor of US NSA Equation Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Bvp47 - a Top-tier Backdoor of US NSA Equation Group
-
Chinese Experts Uncover Details of Equation Group's Bvp47 Covert Hacking Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Experts Uncover Details of Equation Group's Bvp47 Covert Hacking Tool
-
The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Detailsfor The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en
-
The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf
The original link failed its last check. Original publisher Detailsfor The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf
-
A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_jumping_the_air_gap_wp
-
SMB Worm “Indexsinas” Uses Lateral Movement to Infect Whole Networks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SMB Worm “Indexsinas” Uses Lateral Movement to Infect Whole Networks
-
Glupteba back on track spreading via EternalBlue exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Glupteba back on track spreading via EternalBlue exploits
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sanctioned Firm Accused of Helping Russian Intelligence Was Part of Microsoft’s Early Vuln Access Program — MAPP
-
research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
-
The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
-
Voltron STA The curious case of 0xFancyFilter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Voltron STA The curious case of 0xFancyFilter
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
An overview of targeted attacks and APTs on Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An overview of targeted attacks and APTs on Linux
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lucifer- New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nazar- Spirits of the Past
-
Nazar_ Spirits of the Past - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Nazar_ Spirits of the Past - Check Point Research
-
Quick look at Nazar backdoor - Capabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Quick look at Nazar backdoor - Capabilities
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nazar- A Lost Amulet
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Wikipedia Entry on Equation Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wikipedia Entry on Equation Group
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Equation Group
-
UPSynergy_ Chinese-American Spy vs. Spy Story
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UPSynergy_ Chinese-American Spy vs. Spy Story
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Buckeye- Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye- Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
-
Buckeye_ Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye_ Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q2 2017
-
Kaspersky's 'Slingshot' report burned an ISIS-focused intelligence operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky's 'Slingshot' report burned an ISIS-focused intelligence operation
-
ShadowBrokers are back demanding nearly $4m and offering 2 dumps per month
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowBrokers are back demanding nearly $4m and offering 2 dumps per month
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WannaCry ransomware that infected Telefonica and NHS hospitals is spreading aggressively, with over 50,000 attacks so far today
-
ShadowBrokers Dump More Equation Group Hacks, Auction File Password
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowBrokers Dump More Equation Group Hacks, Auction File Password
-
EquationDrug rootkit analysis (mstcp32.sys)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EquationDrug rootkit analysis (mstcp32.sys)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remsec driver analysis
-
‘Shadow Brokers’ Whine That Nobody Is Buying Their Hacked NSA Files
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ‘Shadow Brokers’ Whine That Nobody Is Buying Their Hacked NSA Files
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SECONDDATE in action
-
A few notes on SECONDDATE's C&C protocol
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A few notes on SECONDDATE's C&C protocol
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TADAQUEOUS moments
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FEINTCLOUD
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BLATSTING FUNKSPIEL
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Shadow Brokers
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor The Shadow Brokers
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
ENISA - Threat Landscape - 2015.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ENISA - Threat Landscape - 2015.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015年中国高持续性威胁(APT)研究报告
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky - Duqu2 FAQ.pdf
-
The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns
-
Inside The Equationdrug Espionage Platform
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Inside The Equationdrug Espionage Platform
-
Inside the EquationDrug Espionage Platform
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the EquationDrug Espionage Platform
-
Ali Baba, the APT group from the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ali Baba, the APT group from the Middle East
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A_Fanny_Equation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog_equation-the-death-star
-
Equation- The Death Star of Malware Galaxy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Equation- The Death Star of Malware Galaxy
-
How “omnipotent” hackers tied to NSA hid for 14 years—and were found at last
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How “omnipotent” hackers tied to NSA hid for 14 years—and were found at last
-
Equation Group: Questions And Answers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Equation Group: Questions And Answers
-
Stuxnet/Duqu: The Evolution of Drivers - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Stuxnet/Duqu: The Evolution of Drivers - Securelist
-
A quick analysis of the latest Shadow Brokers dump
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A quick analysis of the latest Shadow Brokers dump
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor stuxnet_0_5_the_missing_link
-
The Flame- Questions and Answers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Flame- Questions and Answers
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Stuxnet
Newest first. Details opens the report in Explore.