logo

Chinese APT Group, Used Stolen NSA Hacking Tools Before Shadow Brokers

ID: 5dc9a407-870c-5e68-a931-e6fd8e0b4203

STIX ID: report--5dc9a407-870c-5e68-a931-e6fd8e0b4203

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2019-05-09

Date Updated: 2026-05-08

Author: Elizabeth Montalbano

...
...

Symantec reporting indicates Chinese-linked APT 'Buckeye' (APT3/Gothic Panda) deployed a variant of the DoublePulsar backdoor delivered via the Bemstour exploit in March 2016, suggesting the group used or replicated NSA Equation Group tools before those tools were publicly leaked by Shadow Brokers; the article highlights CVE-2017-0143 and a Symantec-discovered zero-day (CVE-2019-0703) in discussing the exploits and warns of the strategic risk when state cyber-weapons are exposed and repurposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.