<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Equation_Group</id>
	<title>Equation Group - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Equation_Group"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Equation_Group&amp;action=history"/>
	<updated>2026-09-25T05:01:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Equation_Group&amp;diff=430190&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Equation_Group&amp;diff=430190&amp;oldid=prev"/>
		<updated>2023-09-25T18:40:51Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|Cyber attack group}}&lt;br /&gt;
{{Infobox organization&lt;br /&gt;
| name                = Equation Group&lt;br /&gt;
| named_after         =&lt;br /&gt;
| image               =&lt;br /&gt;
| image_size          =&lt;br /&gt;
| alt                 =&lt;br /&gt;
| caption             =&lt;br /&gt;
| logo                =&lt;br /&gt;
| logo_size           =&lt;br /&gt;
| logo_alt            =&lt;br /&gt;
| logo_caption        =&lt;br /&gt;
| abbreviation        =&lt;br /&gt;
| motto               =&lt;br /&gt;
| predecessor         =&lt;br /&gt;
| merged              =&lt;br /&gt;
| successor           =&lt;br /&gt;
| formation           = &amp;lt;!-- use {{start date and age|YYYY|MM|DD}} --&amp;gt;&lt;br /&gt;
| founder             =&lt;br /&gt;
| founding_location   =&lt;br /&gt;
| extinction          = &amp;lt;!-- use {{end date and age|YYYY|MM|DD}} --&amp;gt;&lt;br /&gt;
| merger              =&lt;br /&gt;
| type                = [[Advanced persistent threat]]&lt;br /&gt;
| status              =&lt;br /&gt;
| purpose             =&lt;br /&gt;
| headquarters        =&lt;br /&gt;
| location            = [[United States]]&lt;br /&gt;
| coords              = &amp;lt;!-- {{coord|LAT|LON|display=inline, title}} --&amp;gt;&lt;br /&gt;
| region              =&lt;br /&gt;
| services            =&lt;br /&gt;
| products            = [[Stuxnet]], [[Flame (malware)|Flame]], [[EternalBlue]]&lt;br /&gt;
| methods             =&lt;br /&gt;
| fields              =&lt;br /&gt;
| sec_gen             =&lt;br /&gt;
| key_people          =&lt;br /&gt;
| main_organ          =&lt;br /&gt;
| parent_organization = &lt;br /&gt;
* [[National Security Agency]]&lt;br /&gt;
** [[Signals Intelligence Directorate]]&lt;br /&gt;
*** [[Tailored Access Operations]]&lt;br /&gt;
| subsidiaries        =&lt;br /&gt;
| secessions          =&lt;br /&gt;
| affiliations        =&lt;br /&gt;
| staff               =&lt;br /&gt;
| staff_year          =&lt;br /&gt;
| volunteers          =&lt;br /&gt;
| volunteers_year     =&lt;br /&gt;
| formerly            =&lt;br /&gt;
| footnotes           =&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;Equation Group&amp;#039;&amp;#039;&amp;#039;, classified as an [[advanced persistent threat]], is a highly sophisticated [[Threat (computer)#Threat agents or actors|threat actor]] suspected of being tied to the [[Tailored Access Operations]] (TAO) unit of the [[United States]] [[National Security Agency]] (NSA).&amp;lt;ref&amp;gt;{{cite journal|last=Fox-Brewster|first=Thomas|date=February 16, 2015|title=Equation = NSA? Researchers Uncloak Huge &amp;#039;American Cyber Arsenal&amp;#039; |url=https://www.forbes.com/sites/thomasbrewster/2015/02/16/nsa-equation-cyber-tool-treasure-chest/|journal=[[Forbes]] |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite news|url=https://www.reuters.com/article/idUSL1N0VN15J20150216|title=Russian researchers expose breakthrough U.S. spying program|last=Menn|first=Joseph|date=February 17, 2015 |publisher=[[Reuters]]|access-date=November 24, 2015}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite news|title=The nsa was hacked snowden documents confirm|work=[[The Intercept]]|url=https://theintercept.com/2016/08/19/the-nsa-was-hacked-snowden-documents-confirm/|date=19 August 2016|access-date=19 August 2016}}&amp;lt;/ref&amp;gt; [[Kaspersky Labs]] describes them as one of the most sophisticated cyber attack groups in the world and &amp;quot;the most advanced (...) we have seen&amp;quot;, operating alongside the creators of [[Stuxnet]] and [[Flame (malware)|Flame]].&amp;lt;ref name=&amp;quot;malware-galaxy&amp;quot;&amp;gt;{{cite web |url=https://securelist.com/equation-the-death-star-of-malware-galaxy/68750/ |title=Equation: The Death Star of Malware Galaxy |author=GReAT |date=February 16, 2015 |website=Securelist.com |publisher=[[Kaspersky Lab]] |access-date=August 16, 2016 |quote=&amp;#039;&amp;#039;SecureList&amp;#039;&amp;#039;, Costin Raiu (director of Kaspersky Lab&amp;#039;s global research and analysis team): &amp;quot;It seems to me Equation Group are the ones with the coolest toys. Every now and then they share them with the Stuxnet group and the Flame group, but they are originally available only to the Equation Group people. Equation Group are definitely the masters, and they are giving the others, maybe, bread crumbs. From time to time they are giving them some goodies to integrate into Stuxnet and Flame.&amp;quot;}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=ars/&amp;gt; Most of their targets have been in [[Iran]], [[Russia]], [[Pakistan]], [[Afghanistan]], [[India]], [[Syria]] and [[Mali]].&amp;lt;ref name=&amp;quot;ars&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The name originated from the group&amp;#039;s extensive use of encryption. By 2015, Kaspersky documented 500 [[malware]] infections by the group in at least 42 countries, while acknowledging that the actual number could be in the tens of thousands due to its self-terminating protocol.&amp;lt;ref name=ars&amp;gt;{{cite news |title=How &amp;quot;omnipotent&amp;quot; hackers tied to NSA hid for 14 years—and were found at last |work=[[Ars Technica]] |url=https://arstechnica.com/security/2015/02/how-omnipotent-hackers-tied-to-the-nsa-hid-for-14-years-and-were-found-at-last/ |first=Dan |last=Goodin |date=February 16, 2015 |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=http://www.pcworld.com/article/2884952/equation-cyberspies-use-unrivaled-nsastyle-techniques-to-hit-iran-russia.html |title=Destroying your hard drive is the only way to stop this super-advanced malware |first=Jeremy |last=Kirk |date=17 February 2015 |work=[[PCWorld]] |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In 2017, WikiLeaks [[Vault 7|published a discussion]] held within the [[Central Intelligence Agency|CIA]] on how it had been possible to identify the group.&amp;lt;ref name=&amp;quot;Goodin CIA&amp;quot;&amp;gt;{{cite web|last1=Goodin|first1=Dan|title=After NSA hacking exposé, CIA staffers asked where Equation Group went wrong|url=https://arstechnica.com/security/2017/03/after-nsa-hacking-expose-cia-staffers-asked-where-equation-group-went-wrong/|website=[[Ars Technica]]|date=7 March 2017|access-date=21 March 2017}}&amp;lt;/ref&amp;gt; One commenter wrote that &amp;quot;the Equation Group as labeled in the report does not relate to a specific group but rather a collection of tools&amp;quot; used for hacking.&amp;lt;ref name=&amp;quot;What did Equation do wrong&amp;quot;&amp;gt;{{cite web |title=What did Equation do wrong, and how can we avoid doing the same?|url=https://wikileaks.org/ciav7p1/cms/page_14588809.html |website=Vault 7|publisher=[[WikiLeaks]]|access-date=21 March 2017}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Discovery==&lt;br /&gt;
At the Kaspersky Security Analysts Summit held in Mexico on February 16, 2015, Kaspersky Lab announced its discovery of the Equation Group. According to Kaspersky Lab&amp;#039;s report, the group has been active since at least 2001, with more than 60 actors.&amp;lt;ref name=&amp;quot;kaspersky&amp;quot;&amp;gt;{{Cite web |title=Equation Group: The Crown Creator of Cyber-Espionage |work=Kaspersky Lab |url=http://www.kaspersky.com/about/news/virus/2015/Equation-Group-The-Crown-Creator-of-Cyber-Espionage |date=February 16, 2015 |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt; The malware used in their operations, dubbed EquationDrug and GrayFish, is found to be capable of reprogramming [[hard disk drive]] [[firmware]].&amp;lt;ref name=&amp;quot;malware-galaxy&amp;quot;/&amp;gt; Because of the advanced techniques involved and high degree of covertness, the group is suspected of ties to the NSA, but Kaspersky Lab has not identified the actors behind the group.&lt;br /&gt;
&lt;br /&gt;
==Probable links to Stuxnet and the NSA==&lt;br /&gt;
In 2015 Kaspersky&amp;#039;s research findings on the Equation Group noted that its loader, &amp;quot;Grayfish&amp;quot;, had similarities to a previously discovered loader, &amp;quot;Gauss&amp;quot;,{{Plain link|https://github.com/loneicewolf/Gauss-Src|&amp;lt;sup&amp;gt;&amp;lt;nowiki&amp;gt;[repository]&amp;lt;/nowiki&amp;gt;&amp;lt;/sup&amp;gt;}} from another attack series, and separately noted that the Equation Group used two zero-day attacks later used in [[Stuxnet]]; the researchers concluded that &amp;quot;the similar type of usage of both exploits together in different computer worms, at around the same time, indicates that the EQUATION group and the Stuxnet developers are either the same or working closely together&amp;quot;.&amp;lt;ref name=&amp;quot;Kaspersky1&amp;quot;&amp;gt;{{cite web |url=https://securelist.com/files/2015/02/Equation_group_questions_and_answers.pdf |title=Equation Group: Questions and Answers (Version: 1.5) |date=February 2015 |publisher=[[Kaspersky Lab]] |access-date=November 24, 2015 |archive-url=https://web.archive.org/web/20150217023145/https://securelist.com/files/2015/02/Equation_group_questions_and_answers.pdf |archive-date=February 17, 2015 |url-status=dead }}&amp;lt;/ref&amp;gt;{{rp|13}}&lt;br /&gt;
&lt;br /&gt;
===Firmware===&lt;br /&gt;
They also identified that the platform had at times been spread by [[interdiction]] (interception of legitimate CDs sent by a scientific conference organizer by [[mail]]),&amp;lt;ref name=&amp;quot;Kaspersky1&amp;quot; /&amp;gt;{{rp|15}} and that the platform had the &amp;quot;unprecedented&amp;quot; ability to infect and be transmitted through the [[hard drive]] [[firmware]] of several major hard drive manufacturers, and create and use hidden disk areas and virtual disk systems for its purposes, a feat which would require access to the manufacturer&amp;#039;s [[source code]] to achieve,&amp;lt;ref name=&amp;quot;Kaspersky1&amp;quot; /&amp;gt;{{rp|16–18}} and that the tool was designed for surgical precision, going so far as to exclude specific countries by IP and allow targeting of specific usernames on [[discussion forum]]s.&amp;lt;ref name=&amp;quot;Kaspersky1&amp;quot;/&amp;gt;{{rp|23–26}}&lt;br /&gt;
&lt;br /&gt;
===Codewords and timestamps===&lt;br /&gt;
The NSA codewords &amp;lt;!-- The terms &amp;quot;BACKSNARF&amp;quot; and &amp;quot;Grok&amp;quot; are ancient MIT/SAIL usages from the late 70s and are common throughout computer geekdom, --&amp;gt; &amp;quot;STRAITACID&amp;quot; and &amp;quot;STRAITSHOOTER&amp;quot; have been found inside the malware. In addition, [[timestamps]] in the malware seem to indicate that the programmers worked overwhelmingly Monday–Friday in what would correspond to a 08:00–17:00 (8:00 AM - 5:00 PM) workday in an Eastern United States time zone.&amp;lt;ref&amp;gt;{{cite web |url=https://arstechnica.com/security/2015/03/new-smoking-gun-further-ties-nsa-to-omnipotent-equation-group-hackers/ |title=New smoking gun further ties NSA to omnipotent &amp;quot;Equation Group&amp;quot; hackers |first=Dan |last=Goodin |date=March 11, 2015 |work=Ars Technica |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===The LNK exploit===&lt;br /&gt;
Kaspersky&amp;#039;s global research and analysis team, otherwise known as GReAT, claimed to have found a piece of malware that contained Stuxnet&amp;#039;s &amp;quot;privLib&amp;quot; in 2008.&amp;lt;ref&amp;gt;{{cite web |url=https://securelist.com/blog/research/68787/a-fanny-equation-i-am-your-father-stuxnet/|title=A Fanny Equation: &amp;quot;I am your father, Stuxnet&amp;quot; |publisher=Kaspersky Lab |date=February 17, 2015 |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt; Specifically it contained the LNK exploit found in Stuxnet in 2010. Fanny is classified as a worm that affects certain [[Microsoft Windows|Windows operating systems]] and attempts to spread laterally via network connection or [[Universal Serial Bus|USB storage]].{{Plain link|https://github.com/loneicewolf/fanny.bmp|&amp;lt;sup&amp;gt;&amp;lt;nowiki&amp;gt;[repository]&amp;lt;/nowiki&amp;gt;&amp;lt;/sup&amp;gt;}} Kaspersky stated that they suspect that the Equation Group has been around longer than Stuxnet, based on the recorded compile time of Fanny.&amp;lt;ref name=&amp;quot;malware-galaxy&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Link to IRATEMONK===&lt;br /&gt;
[[File:NSA IRATEMONK.jpg|thumb|The NSA&amp;#039;s listing of its [[Tailored Access Operations]] program named IRATEMONK from the [[NSA ANT catalog]].]]&lt;br /&gt;
[[F-Secure]] claims that the Equation Group&amp;#039;s malicious hard drive [[firmware]] is [[Tailored Access Operations|TAO]] program &amp;quot;IRATEMONK&amp;quot;,&amp;lt;ref name=&amp;quot;FSecure&amp;quot;&amp;gt;{{cite web|url=https://www.f-secure.com/weblog/archives/00002791.html |title=The Equation Group Equals NSA / IRATEMONK |work=[[F-Secure]] Weblog : News from the Lab |date=February 17, 2015 |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt; one of the items from the [[NSA ANT catalog]] exposed in a 2013 &amp;#039;&amp;#039;Der Spiegel&amp;#039;&amp;#039; article. IRATEMONK provides the attacker with an ability to have their [[Application software|software application]] persistently installed on desktop and laptop computers, despite the disk being [[Disk formatting|formatted]], its [[Data erasure|data erased]] or the operating system re-installed. It infects the hard drive firmware, which in turn adds instructions to the disk&amp;#039;s [[master boot record]] that causes the software to install each time the computer is [[Booting|booted up]].&amp;lt;ref name=&amp;quot;IRATEMONK&amp;quot;/&amp;gt; It is capable of infecting certain hard drives from [[Seagate Technology|Seagate]], [[Maxtor]], [[Western Digital]], [[Samsung]],&amp;lt;ref name=&amp;quot;IRATEMONK&amp;quot;&amp;gt;{{cite web |url=https://www.schneier.com/blog/archives/2014/01/iratemonk_nsa_e.html |first=Bruce |last=Schneier |title=IRATEMONK: NSA Exploit of the Day |work=Schneier on Security |date=January 31, 2014 |access-date=November 24, 2015}}&amp;lt;/ref&amp;gt; [[IBM]], [[Micron Technology]] and [[Toshiba]].&amp;lt;ref name=&amp;quot;malware-galaxy&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==2016 breach of the Equation Group==&lt;br /&gt;
In August 2016, a hacking group calling itself &amp;quot;[[The Shadow Brokers]]&amp;quot; announced that it had stolen malware code from the Equation Group.&amp;lt;ref&amp;gt;{{cite news |url=https://arstechnica.com/security/2016/08/group-claims-to-hack-nsa-tied-hackers-posts-exploits-as-proof/ |first=Dan |last=Goodin |title=Group claims to hack NSA-tied hackers, posts exploits as proof |date=August 15, 2016 |access-date=August 19, 2016 |newspaper=Ars Technica}}&amp;lt;/ref&amp;gt; Kaspersky Lab noticed similarities between the stolen code and earlier known code from the Equation Group malware samples it had in its possession including quirks unique to the Equation Group&amp;#039;s way of implementing the [[RC6]] encryption algorithm, and therefore concluded that this announcement is legitimate.&amp;lt;ref&amp;gt;{{cite news |url=https://arstechnica.com/security/2016/08/code-dumped-online-came-from-omnipotent-nsa-tied-hacking-group/ |title=Confirmed: hacking tool leak came from &amp;quot;omnipotent&amp;quot; NSA-tied group |first=Dan |last=Goodin |date=August 16, 2016 |access-date=August 19, 2016 |newspaper=Ars Technica}}&amp;lt;/ref&amp;gt; The most recent dates of the stolen files are from June 2013, thus prompting [[Edward Snowden]] to speculate that a likely lockdown resulting from his leak of the [[Global surveillance disclosures (2013–present)|NSA&amp;#039;s global and domestic surveillance efforts]] stopped The Shadow Brokers&amp;#039; breach of the Equation Group. Exploits against [[Cisco Adaptive Security Appliance]]s and [[Fortinet]]&amp;#039;s firewalls were featured in some malware samples released by The Shadow Brokers.&amp;lt;ref name=&amp;quot;EXTRABACON&amp;quot;&amp;gt;{{cite news |url=https://www.theregister.co.uk/2016/08/17/cisco_two_shadow_brokers_vulnerabilities_real/ |first=Iain |last=Thomson |title=Cisco confirms two of the Shadow Brokers&amp;#039; &amp;#039;NSA&amp;#039; vulns are real |date=August 17, 2016 |access-date=August 19, 2016 |newspaper=[[The Register]]}}&amp;lt;/ref&amp;gt; EXTRABACON, a [[Simple Network Management Protocol]] exploit against Cisco&amp;#039;s ASA software, was a [[Zero-day (computing)|zero-day exploit]] as of the time of the announcement.&amp;lt;ref name=&amp;quot;EXTRABACON&amp;quot;/&amp;gt; Juniper also confirmed that its NetScreen firewalls were affected.&amp;lt;ref&amp;gt;{{cite news |title=Equation Group exploit hits newer Cisco ASA, Juniper Netscreen |url=https://www.theregister.co.uk/2016/08/24/equation_group_exploit_expanded_to_target_cisco_924_asa_boxes/ |first=Darren |last=Pauli |date=August 24, 2016 |access-date=August 30, 2016 |newspaper=[[The Register]]}}&amp;lt;/ref&amp;gt;  The [[EternalBlue]] exploit was used to conduct the damaging worldwide [[WannaCry ransomware attack]].&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[Global surveillance disclosures (2013–present)]]&lt;br /&gt;
* [[United States intelligence operations abroad]]&lt;br /&gt;
* [[Firmware#Firmware hacking|Firmware hacking]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist|30em}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;[https://web.archive.org/web/20150217023145/https://securelist.com/files/2015/02/Equation_group_questions_and_answers.pdf Equation Group: Questions and Answers]&amp;#039;&amp;#039; by [[Kaspersky Lab]], Version: 1.5, February 2015&lt;br /&gt;
* [https://securelist.com/blog/research/68787/a-fanny-equation-i-am-your-father-stuxnet/ A Fanny Equation: &amp;quot;I am your father, Stuxnet&amp;quot;] by [[Kaspersky Lab]], February 2015&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/loneicewolf/fanny.bmp fanny.bmp source - at GitHub], November 30, 2020&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/loneicewolf/fanny.bmp/blob/main/Reports/Fanny.BMP(DementiaWheel)_Technical_Report_By_WilliamMartens-2021-10Feb.pdf Technical Write-up - at GitHub], February 10, 2021&lt;br /&gt;
&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
[[Category:Cyberwarfare in the United States]]&lt;br /&gt;
[[Category:National Security Agency operations]]&lt;br /&gt;
[[Category:Rootkits]]&lt;br /&gt;
[[Category:American advanced persistent threat groups]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;br /&gt;
[[Category:Cyberwarfare in Iran]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>