top of page
Mitre
Alias
Tilded Team, Eqgrp, Equation Group, G0020, Platinum Colony
Country
United States, Usa
Sponsor
United States. State-sponsored, Believed To Be Tied To The Nsa�s Tailored Access Operations Unit, State-sponsored
Motivation
Information Theft And Espionage, Sabotage And Destruction
First Seen
2001
Description
(Ars Technica) Kaspersky researchers have documented 500 infections by Equation Group in at least 42 countries, with Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali topping the list. Because of a self-destruct mechanism built into the malware, the researchers suspect that this is just a tiny percentage of the total; the actual number of victims likely reaches into the tens of thousands.
A long list of almost superhuman technical feats illustrate Equation Group�s extraordinary skill, painstaking work, and unlimited resources. They include:
� The use of virtual file systems, a feature also found in the highly sophisticated Regin malware. Recently published documents provided by Ed Snowden indicate that the NSA used Regin to infect the partly state-owned Belgian firm Belgacom.
� The stashing of malicious files in multiple branches of an infected computer�s registry. By encrypting all malicious files and storing them in multiple branches of a computer�s Windows registry, the infection was impossible to detect using antivirus software.
� Redirects that sent iPhone users to unique exploit Web pages. In addition, infected machines reporting to Equation Group command servers identified themselves as Macs, an indication that the group successfully compromised both iOS and OS X devices.
� The use of more than 300 Internet domains and 100 servers to host a sprawling command and control infrastructure.
� USB stick-based reconnaissance malware to map air-gapped networks, which are so sensitive that they aren�t connected to the Internet. Both Stuxnet and the related Flame malware platform also had the ability to bridge airgaps.
� An unusual if not truly novel way of bypassing code-signing restrictions in modern versions of Windows, which require that all third-party software interfacing with the operating system kernel be digitally signed by a recognized certificate authority. To circumvent this restriction, Equation Group malware exploited a known vulnerability in an already signed driver for CloneCD to achieve kernel-level code execution.
Taken together, the accomplishments led Kaspersky researchers to conclude that Equation Group is probably the most sophisticated computer attack group in the world, with technical skill and resources that rival the groups that developed Stuxnet and the Flame espionage malware in {{Operation Olympic Games}}.
Other publicly exposed major APT activities from the NSA involve the wholesale worldwide spying from programs such as PRISM and, together with {{GCHQ}}, INCENSER, where various international Internet trunks were tapped.
Targeted
Industries
Government, Nanotechnology, Military, Aerospace, Defense, Energy, Oil And Gas, And Companies Developing Cryptographic Technologies, Education, Media, Telecommunications, Islamic Activists And Scholars, Nuclear Research, Transportation
Targeted
Countries
Bolivia, Saudi Arabia, Hong Kong, Mali, Iraq, Italy, France, Libya, Bosnia And Herzegovina, Kazakhstan, Cyprus, Hungary, Lebanon, Norway, Pakistan, Philippines, Poland, Nicaragua, Switzerland, Venezuela, United Kingdom, China, Malaysia, Russia, Turkey, Germany, Greece, Chile, Botswana, Israel, Syria, Brazil, Yemen, Sudan, Nigeria, Romania, Austria, Netherlands, Uae, Usa, Ecuador, Afghanistan, Iran, Uk, Algeria, Qatar, Japan, Bangladesh, India, Somalia, Belgium, Egypt, Mexico, Finland, Sweden, Thailand, United Arab Emirates, Gabon, Palestine, South Africa, Kenya, Singapore, South Korea, Spain, Jordan
Tools
Lambert
Equationdrug
Equationlaser
Doublefeature
Bvp47
Many Others
Doublepulsar
Regin
Unitedrake
Fanny
Doublefantasy
Darkpulsar
Oddjob
Duqu
Grayfish
Flame
Triplefantasy
Danderspritz
Grok
TTP
T1480
T1564
T1542.002
T1480.001
T1542
T1564.005
T1120
Operations
Performed
Nil
Counter
Operations
'date': '2016-08', 'activity': 'their Arsenal Of 0-day Cyber Weapons Was Stolen By An Actor shadow Brokers, Who Leaked A Large Section On The Internet And Tried To Sell The Rest Afterward. (most Notable Among The Dumps Were 0-days Such As Eternalblue And Eternalromance That Were Used By Other Groups For The Creation Of Infamous Ransomware Explosions Such As Wannacry And Notpetya.'
Information
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064459/Equation_group_questions_and_answers.pdf
https://arstechnica.com/information-technology/2015/02/how-omnipotent-hackers-tied-to-the-nsa-hid-for-14-years-and-were-found-at-last/
https://en.wikipedia.org/wiki/Equation_Group
https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
https://www.electrospaces.net/2014/11/incenser-or-how-nsa-and-gchq-are.html
bottom of page