The Equation Group
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known publicly as the Equation Group also operates under the aliases Longhorn and Lamberts and is believed to be based in the United States of America. Public reporting links the Equation Group to the National Security Agency, with researchers noting that the group’s malware bears technical DNA similar to other state‑sponsored tools such as Flame, Duqu and Stuxnet. The observed use of Regin, a spyware suite, indicates an espionage‑oriented objective rather than financial gain or destructive disruption. This attribution rests on multiple sources, including Kaspersky Lab’s research and documents leaked by Edward Snowden that connect Regin to an NSA attack tool called QWERTY.
The Equation Group has been observed targeting a range of sectors that include telecommunications, hospitality, energy, airline and research industries, as well as government entities. Notable victims cited in open sources are the Belgian telecom operator Belgacom, the Belgian cryptographer Jean‑Jacques Quisquater, and a senior official in the German Federal Chancellery whose laptop was infected with Regin in October 2015. These infections demonstrate a geographic focus that spans Europe, particularly Belgium and Germany, while the actor’s alleged U.S. location suggests a trans‑Atlantic operational reach. The campaigns described are part of a longer‑running effort that Kaspersky noted had been active since at least 2008 and remained undetected for roughly fourteen years before discovery.
Technical analysis of the group’s tooling highlights the Regin malware framework, which consists of dozens of interchangeable modules allowing attackers to customize functionality for each target. Infection techniques referenced in the reporting include the exploitation of two zero‑day vulnerabilities to write malicious code into hard‑drive firmware and the use of web‑redirect mechanisms to compromise iPhone users. A keylogging component identified as QWERTY operates within a larger framework dubbed WARRIORPRIDE, as described in Snowden‑leaked documents. Together, these tactics illustrate a persistent focus on stealth, persistence and data collection rather than rapid financial theft or overt destruction.
Incidents
Attributed incidents are available to members.
1 incident