ATT&CKGroupsEquation

Equation

G0020

Threat group.View on attack.mitre.org

About this group

Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1120
Peripheral Device Discovery

Equation has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware.

T1480.001
Environmental Keying

Equation has been observed utilizing environmental keying in payload delivery.

T1542.002
Component Firmware

Equation is known to have the capability to overwrite the firmware on hard drives from some manufacturers.

T1564.005
Hidden File System

Equation has used an encrypted virtual file system stored in the Windows Registry.

Software0

None recorded.

Campaigns0

None recorded.

References1

  1. Kaspersky Equation QA Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, February). Equation Group: Questions and Answers. Retrieved December 21, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.