Equation

MITRE ATT&CK: G0020 View on attack.mitre.org

Aliases: Tilded Team, EQGRP, Equation

First seen
2001-01-01 00:00:00
Origin
US
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-07-16 00:44:01
Profile updated
2026-07-07 11:52:30

Targeted industries: defense-and-aerospace energy-and-utilities government-and-public-sector technology-and-telecommunications

Context

Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.

Detection coverage

  • 2 Sigma rules

Malware & tools used

  • Peripheral Device Discovery (attack-pattern)
  • Environmental Keying (attack-pattern)
  • Component Firmware (attack-pattern)
  • Hidden File System (attack-pattern)

Related threat objects

Reports & references

  • Wikipedia — Equation Group (report)
  • cfr.org — Equation Group (report)
  • arstechnica.com — How Omnipotent Hackers Tied To The Nsa Hid For 14 Years And Were Found At Last (report)
  • dropbox.com — Whitepaper%20Shadow%20Broker%20 %20Equation%20Group%20Hack (report)
  • Wikipedia — Stuxnet (report)
  • media.kasperskycontenthub.com — Equation Group Questions And Answers (report)
  • MITRE ATT&CK — G0020 (report)

External references