6 ms·
I found this to match your request: Together with additional artifacts that match Equation Group artifacts and habits shared between all exploits even as far b
by FreshFries 6y ago
I found this to match your request:
Together with additional artifacts that match Equation Group artifacts and habits shared between all exploits even as far back as 2008, we can safely conclude the following:
- Equation Group’s EpMe exploit, existing since at least 2013, is the original exploit for the vulnerability later labeled CVE-2017-0005.
- Somewhere around 2014, APT31 managed to capture both the 32-bit and 64-bit samples of the EpMe Equation Group exploit.
- They replicated them to construct “Jian”, and used this new version of the exploit alongside their unique multi-staged packer.
- Jian was caught by Lockheed Martin’s IRT and reported to Microsoft, which patched the vulnerability in March 2017 and labeled it CVE-2017-0005.
TL;DR
CheckPoint (the firewall company) analysed the #R@$$ out of exploits used by the NSA (Equation Group) and the Chinese equivalent (APT31) und found that the later captured & reused the exploit of the first, making a point that "There is a theory which states that if anyone will ever manage to steal and use nation-grade cyber tools, any network would become untrusted, and the world would become a very dangerous place to live in."