EquationDrug

First seen
2015-02-16 00:00:00
Malware type
rootkit, backdoor
Family
Malware family
Last IoC activity
2026-05-21 07:04:59
Profile updated
2026-07-07 14:58:34

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:ir

Context

EquationDrug is a sophisticated malware family associated with high-profile espionage campaigns. Known for its advanced capabilities, it has been used by nation-state actors to infiltrate and monitor high-value targets across various sectors.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Equationdrug_Auto (yara-rule)

Reports & references

  • Kaspersky — 68750 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Equationdrug (report)
  • artemonsecurity.blogspot.com — Equationdrug Rootkit Analysis Mstcp32Sys (report)
  • Kaspersky — 69203 (report)
  • mp.weixin.qq.com — 3Zqhn32Nb6P Lwndb2O2Zq (report)

External references