Shadow Brokers and the Equation Group tools
Alleged: Reported or claimed; not established in the public record.
From August 2016 a group calling itself the Shadow Brokers published hacking tools said to belong to the Equation Group, the cyber-espionage actor Kaspersky described in 2015. A further release on 14 April 2017, "Lost in Translation", contained exploits later used in the WannaCry ransomware outbreak.
Confirmed
Rapid7 reported that vendors confirmed the first leak was real. Microsoft issued the MS17-010 patch on 14 March 2017 and said WannaCrypt used the EternalBlue exploit. Check Point counted over 400,000 DoublePulsar infections before WannaCry.
Claimed, disputed or not established
The NSA origin is the attribution of researchers; the sources opened carry no official US confirmation. Rapid7 said the April 2017 dump held no zero-days and that four of its exploits were already patched. Who the Shadow Brokers are is not established.
Reported impact
Large-scale ransomware infections on unpatched systems, and a debate about governments stockpiling vulnerabilities.
Sources (opened in a new tab)
- Rapid7: the Shadow Brokers leaked exploits FAQ ↗https://www.rapid7.com/blog/post/2017/04/18/the-shadow-brokers-leaked-exploits-faq/
- Microsoft: WannaCrypt ransomware worm targets out-of-date systems ↗https://www.microsoft.com/en-us/security/blog/2017/05/12/wannacrypt-ransomware-worm-targets-out-of-date-systems/
- Check Point Research: analysing the leaked tools ↗https://research.checkpoint.com/2017/brokers-shadows-analyzing-vulnerabilities-attacks-spawned-leaked-nsa-hacking-tools/
- Check Point Research: EternalBlue, everything you need to know ↗https://research.checkpoint.com/2017/eternalblue-everything-know/
- Kaspersky: Equation Group, the crown creator of cyber-espionage ↗https://www.kaspersky.com/about/press-releases/equation-group-the-crown-creator-of-cyber-espionage
Connected
- Agencies: NSA
- Related leaks: Vault 7: CIA hacking tools
- Case board · Timeline (2016) · Document vault · How we verify leaks
This page describes and cites public reporting. It does not host or link to leaked files, and it names no private individuals.
