EquationDrug
- First seen
- 2015-02-16 00:00:00
- Malware type
- rootkit, backdoor
- Family
- Malware family
- Last IoC activity
- 2026-05-21 07:04:59
- Profile updated
- 2026-07-07 14:58:34
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:us country_code:ru country_code:ir
Context
EquationDrug is a sophisticated malware family associated with high-profile espionage campaigns. Known for its advanced capabilities, it has been used by nation-state actors to infiltrate and monitor high-value targets across various sectors.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Equationdrug_Auto (yara-rule)
Reports & references
- Kaspersky — 68750 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Equationdrug (report)
- artemonsecurity.blogspot.com — Equationdrug Rootkit Analysis Mstcp32Sys (report)
- Kaspersky — 69203 (report)
- mp.weixin.qq.com — 3Zqhn32Nb6P Lwndb2O2Zq (report)