Shadow Brokers is the name used by an unidentified actor or group that emerged publicly in 2016 and became notorious for leaking highly sophisticated offensive cyber tools widely assessed to have been stolen from the U.S. National Security Agency’s Equation Group and Tailored Access Operations ecosystem. The persona initially advertised an auction for the material, released samples alongside encrypted archives, and later published substantial portions of the toolset openly, suggesting the auction was at least in part a publicity or influence mechanism rather than a straightforward criminal sale. Shadow Brokers is best known for exposing exploitation frameworks and implants associated with advanced Windows and network intrusion operations, including capabilities later referred to publicly as EternalBlue, EternalRomance, DoublePulsar, and Oddjob. The leaked material demonstrated mature tradecraft in remote exploitation, persistence, lateral movement, and post-compromise operations against enterprise infrastructure and perimeter devices. The disclosures also revealed targeting breadth consistent with state offensive cyber operations and triggered extensive defensive analysis, detection engineering, and patching activity across the industry. The group’s historical significance stems less from direct victim operations than from the downstream impact of its leaks. Tools released under the Shadow Brokers persona were subsequently repurposed in major global incidents, most notably WannaCry and NotPetya, where leaked NSA-linked SMB exploitation capabilities enabled rapid wormable propagation across unpatched Windows environments. Those events caused severe disruption across healthcare, logistics, manufacturing, government, and other sectors worldwide, making Shadow Brokers one of the most consequential leak actors in modern cybersecurity history. Attribution remains unresolved. No individual has been publicly charged as the operator of the Shadow Brokers persona. Competing theories have included an insider or former insider with access to NSA materials and a Russian intelligence-linked information operation or front. While the latter has often been treated as a leading analytical hypothesis in public discussion, definitive attribution is not currently available. The group’s operators used a distinctive public style and intermittent messaging, then largely disappeared after the releases. Shadow Brokers is not primarily characterized as a conventional intrusion set with a stable victimology or a long-running malware family portfolio of its own. Instead, it is best understood as a leak and influence actor whose publication of stolen state cyber capabilities materially altered the threat landscape by enabling broader criminal and state reuse of advanced exploitation tools. Known aliases in the available reporting are limited to Shadow Brokers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mysterious group that surfaced online offering stolen NSA/TAO hacking tools for sale, contributing to public exposure of TAO capabilities.
Released stolen NSA-linked offensive cyber tools, claimed to have breached the Equation Group, attempted to auction the tools, and later publicly dumped them, enabling downstream destructive attacks by other actors.
Enigmatic group that leaked a trove of hacking tools believed to belong to the NSA/Equation Group, likely using the release as a propaganda operation and public dump rather than a genuine auction.
Leaked offensive cyber tools including EternalBlue, which enabled the broader WannaCry outbreak.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.