Fanny

Aliases: DEMENTIAWHEEL

First seen
2008-01-01 00:00:00
Malware type
worm, exploit-kit
Profile updated
2026-07-07 14:42:52

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ir country_code:pk

Context

Fanny is a USB-propagated worm discovered in 2008, used primarily for reconnaissance and weapon delivery in the Middle East and South Asia. It was part of a tailored cyber espionage campaign targeting SCADA and critical infrastructure systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Fanny_Auto (yara-rule)

Reports & references

  • ESET — Eset Jumping The Air Gap Wp (report)
  • fmnagisa.wordpress.com — Revisiting Equationgroups Fanny Worm Or Dementiawheel (report)
  • Kaspersky — 68750 (report)
  • research.checkpoint.com — A Deep Dive Into Doublefeature Equation Groups Post Exploitation Dashboard (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Fanny (report)
  • fmmresearch.files.wordpress.com — Theemeraldconnectionreport Fmmr 2 (report)
  • fmmresearch.wordpress.com — The Emerald Connection Equationgroup Collaboration With Stuxnet (report)

External references