Introduction
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives. Kaspersky Equation QA
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1564.005 Hidden File System
- T1120 Peripheral Device Discovery
- T1480.001 Environmental Keying
- T1542.002 Component Firmware
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- RemoteCMD:
- CyberGate:
- Cyber Eye RAT:
- Remote Utilities:
- RemotePC:
- Xploit:
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [3] Kaspersky Equation QA Kaspersky Labβs Global Research and Analysis Team. (2015, February). Equation Group: Questions and Answers. Retrieved December 21, 2015.