CSIDB logo
Threat actor

Shadow Brokers

Attribution profile

Type
Activist
Location
Russia
Known incidents
5 incidents
First seen
2016-08-13
Last seen
2017-06-27
Updated
2026-08-01 04:19
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as the ShadowBrokers, also referred to as the Shadow Brokers, emerged publically when it claimed to have compromised the Equation Group and obtained previously unseen exploits and implants. The group presented itself as a mysterious entity that leaked a collection of advanced hacking tools bearing digital signatures closely aligned with those used by the Equation Group, a threat actor publicly linked to the National Security Agency or a related United States hacking apparatus. Security researchers at Kaspersky Lab noted that the leaked ShadowBrokers archive contained more than three hundred files sharing functionally identical RC5/RC6 encryption implementations, including the distinctive use of the constant ‑0x61C88647 instead of the standard 0x61C88647, which they interpreted as strong evidence of a direct connection to the Equation Group’s codebase. Kaspersky’s analysis further suggested that the breach of the Equation Group was carried out by a group possibly linked to Russia, motivated by a desire to publicly discredit the Equation Group’s operations.

The ShadowBrokers’ tactics, as evidenced by the leaked archive, centered on the acquisition and dissemination of offensive cyber tools rather than the development of novel malware families. Their disclosed toolset included exploits and implants that mirrored the Equation Group’s capability to deploy zero‑day vulnerabilities, such as those later associated with the Stuxnet worm targeting Iran’s nuclear program and the Flame malware platform focused on the Middle East. By releasing these tools, the ShadowBrokers demonstrated a capability to obtain and redistribute high‑value offensive assets, a tactic that aligns with their stated aim of undermining the credibility of the Equation Group’s hacking campaign. Kaspersky researchers explicitly characterized the ShadowBrokers’ objective as an effort to publicly discredit the Equation Group’s operations, indicating a strategic motive rooted in reputational damage rather than financial gain.

The most prominent operation attributed to the ShadowBrokers is the 2016 leak of the Equation Group’s exploit collection, which brought to light a suite of cyber weapons that had been used in sophisticated state‑sponsored campaigns. This leak exposed tools that had underpinned notable incidents such as the Stuxnet attack on Iranian enrichment facilities and the Flame espionage suite in the Middle East, thereby amplifying the impact of the original Equation Group activities. While the ShadowBrokers did not claim to have conducted those attacks themselves, their distribution of the associated exploits represented a significant amplification of the original threat landscape and prompted widespread defensive responses across multiple sectors and regions. The episode remains a defining example of how the compromise and public release of state‑linked hacking tools can rapidly alter the threat environment for both governmental and private entities worldwide.

Incidents

Attributed incidents are available to members.

5 incidents
CSIDB