🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
EQUATION GROUP

/actor/equation-group/  ·  0 intel reports

Year Established
2001
Attribution
USA (NSA/TAO)
Motivation
Espionage, Critical Infrastructure Access, Global Signals Intelligence
Modus Operandi (MO)
HDD firmware implants, air-gap bridging, nation-state-level zero-days, PRISM-adjacent tooling
Primary Aliases
Tilded Team, Lamberts (partial), The Equation

Equation Group is widely assessed to be the offensive cyber operations arm of the US National Security Agency's Tailored Access Operations (TAO) unit a naming convention reflecting the group's extraordinary technical depth.

Equation Group's malware arsenal, revealed through a combination of Kaspersky research (2015) and the Shadow Brokers leaks (2016-2017), includes capabilities never previously seen in the public threat landscape: the ability to permanently reprogram the firmware of hard disk drives from over a dozen major manufacturers creating persistent implants that survive complete OS reinstallation, disk formatting, and even physical replacement of the drive's operating system. This HDD firmware persistence capability, dubbed "nls_933w.dll," represented a decade-ahead leap beyond any known malware capability at the time of discovery.

Equation Group co-developed Stuxnet with Israeli intelligence Unit 8200. Their IRATEMONK, GRAYFISH, and FANNY implants demonstrated persistent, cross-platform intelligence collection capabilities spanning Windows, Linux, and multiple embedded system architectures.

In 2016, the Shadow Brokers hacking group began leaking Equation Group tools which were subsequently weaponised by North Korea's WannaCry ransomware (2017) and Russia's NotPetya destructive malware (2017), causing an estimated $10+ billion in global damages. The unintended proliferation of NSA cyberweapons through the Shadow Brokers leaks remains one of the most consequential events in cybersecurity history.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles