top of page

Equation Group

Mitre

Alias

Tilded Team, Eqgrp, Equation Group, G0020, Platinum Colony

Country

United States, Usa

Sponsor

United States. State-sponsored, Believed To Be Tied To The Nsa�s Tailored Access Operations Unit, State-sponsored

Motivation

Information Theft And Espionage, Sabotage And Destruction

First Seen

2001

Description

(Ars Technica) Kaspersky researchers have documented 500 infections by Equation Group in at least 42 countries, with Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali topping the list. Because of a self-destruct mechanism built into the malware, the researchers suspect that this is just a tiny percentage of the total; the actual number of victims likely reaches into the tens of thousands.

A long list of almost superhuman technical feats illustrate Equation Group�s extraordinary skill, painstaking work, and unlimited resources. They include:
� The use of virtual file systems, a feature also found in the highly sophisticated Regin malware. Recently published documents provided by Ed Snowden indicate that the NSA used Regin to infect the partly state-owned Belgian firm Belgacom.
� The stashing of malicious files in multiple branches of an infected computer�s registry. By encrypting all malicious files and storing them in multiple branches of a computer�s Windows registry, the infection was impossible to detect using antivirus software.
� Redirects that sent iPhone users to unique exploit Web pages. In addition, infected machines reporting to Equation Group command servers identified themselves as Macs, an indication that the group successfully compromised both iOS and OS X devices.
� The use of more than 300 Internet domains and 100 servers to host a sprawling command and control infrastructure.
� USB stick-based reconnaissance malware to map air-gapped networks, which are so sensitive that they aren�t connected to the Internet. Both Stuxnet and the related Flame malware platform also had the ability to bridge airgaps.
� An unusual if not truly novel way of bypassing code-signing restrictions in modern versions of Windows, which require that all third-party software interfacing with the operating system kernel be digitally signed by a recognized certificate authority. To circumvent this restriction, Equation Group malware exploited a known vulnerability in an already signed driver for CloneCD to achieve kernel-level code execution.

Taken together, the accomplishments led Kaspersky researchers to conclude that Equation Group is probably the most sophisticated computer attack group in the world, with technical skill and resources that rival the groups that developed Stuxnet and the Flame espionage malware in {{Operation Olympic Games}}.

Other publicly exposed major APT activities from the NSA involve the wholesale worldwide spying from programs such as PRISM and, together with {{GCHQ}}, INCENSER, where various international Internet trunks were tapped.

Targeted
Industries

Government, Nanotechnology, Military, Aerospace, Defense, Energy, Oil And Gas, And Companies Developing Cryptographic Technologies, Education, Media, Telecommunications, Islamic Activists And Scholars, Nuclear Research, Transportation

Targeted
Countries

Bolivia, Saudi Arabia, Hong Kong, Mali, Iraq, Italy, France, Libya, Bosnia And Herzegovina, Kazakhstan, Cyprus, Hungary, Lebanon, Norway, Pakistan, Philippines, Poland, Nicaragua, Switzerland, Venezuela, United Kingdom, China, Malaysia, Russia, Turkey, Germany, Greece, Chile, Botswana, Israel, Syria, Brazil, Yemen, Sudan, Nigeria, Romania, Austria, Netherlands, Uae, Usa, Ecuador, Afghanistan, Iran, Uk, Algeria, Qatar, Japan, Bangladesh, India, Somalia, Belgium, Egypt, Mexico, Finland, Sweden, Thailand, United Arab Emirates, Gabon, Palestine, South Africa, Kenya, Singapore, South Korea, Spain, Jordan

Tools

Lambert
Equationdrug
Equationlaser
Doublefeature
Bvp47
Many Others
Doublepulsar
Regin
Unitedrake
Fanny
Doublefantasy
Darkpulsar
Oddjob
Duqu
Grayfish
Flame
Triplefantasy
Danderspritz
Grok

TTP

T1480
T1564
T1542.002
T1480.001
T1542
T1564.005
T1120

Operations
Performed

Nil

Counter
Operations

'date': '2016-08', 'activity': 'their Arsenal Of 0-day Cyber Weapons Was Stolen By An Actor shadow Brokers, Who Leaked A Large Section On The Internet And Tried To Sell The Rest Afterward. (most Notable Among The Dumps Were 0-days Such As Eternalblue And Eternalromance That Were Used By Other Groups For The Creation Of Infamous Ransomware Explosions Such As Wannacry And Notpetya.'

Information

bottom of page