Equationgroup (Sorting)

First seen
2001-01-01 00:00:00
Malware type
exploit-kit, spyware, rootkit
Family
Malware family
Profile updated
2026-07-07 15:00:09

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:us country_code:ir country_code:ru country_code:cn

Context

Equationgroup refers to a sophisticated and highly advanced threat actor suspected of ties with national intelligence agencies. Known for deploying exploit kits, rootkits, and spyware to infiltrate high-value targets across various sectors globally, Equationgroup represents a significant cyber-espionage threat.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Equationgroup (report)
  • laanwj.github.io — Feintcloud (report)
  • laanwj.github.io — Blatsting Rsa (report)
  • research.checkpoint.com — A Deep Dive Into Doublefeature Equation Groups Post Exploitation Dashboard (report)
  • brandefense.io — Equation Apt Group (report)
  • laanwj.github.io — Blatsting Command And Control (report)
  • laanwj.github.io — Buzzdirection (report)
  • laanwj.github.io — Seconddate Adventures (report)
  • laanwj.github.io — Tadaqueos (report)
  • laanwj.github.io — Seconddate Cnc (report)
  • laanwj.github.io — Blatsting (report)
  • laanwj.github.io — Blatsting Lp Transcript (report)

External references