Equation Group Dump Analysis and Full RCE on Win7 on…
ID: 8de1de2e-3b92-5e56-b0f0-571bc963ae5b
STIX ID: report--8de1de2e-3b92-5e56-b0f0-571bc963ae5b
Feed Name: TrustedSec blog
TrustedSec analyzed the Shadow Brokers dump attributed to the Equation Group, documenting a set of Windows zero-day exploits and implants (including EternalBlue and DoublePulsar), an exploitation framework (FuzzBunch), and a Java-based C2 (DanderSpritz); the blog details successful exploitation of a Windows 7 test host, DLL injection and payload pivoting to Cobalt Strike, and notes Microsoft mitigations (MS17-010) while warning about exposed services and the broad impact of the leak.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
