Equation
MITRE ATT&CK: G0020 View on attack.mitre.org
Aliases: Tilded Team, EQGRP, Equation
- First seen
- 2001-01-01 00:00:00
- Origin
- US
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-16 00:44:01
- Profile updated
- 2026-07-07 11:52:30
Targeted industries: defense-and-aerospace energy-and-utilities government-and-public-sector technology-and-telecommunications
Context
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.
Detection coverage
- 2 Sigma rules
Malware & tools used
- Peripheral Device Discovery (attack-pattern)
- Environmental Keying (attack-pattern)
- Component Firmware (attack-pattern)
- Hidden File System (attack-pattern)
Related threat objects
- Longhorn (threat-actor)
Reports & references
- Wikipedia — Equation Group (report)
- cfr.org — Equation Group (report)
- arstechnica.com — How Omnipotent Hackers Tied To The Nsa Hid For 14 Years And Were Found At Last (report)
- dropbox.com — Whitepaper%20Shadow%20Broker%20 %20Equation%20Group%20Hack (report)
- Wikipedia — Stuxnet (report)
- media.kasperskycontenthub.com — Equation Group Questions And Answers (report)
- MITRE ATT&CK — G0020 (report)