Equation
G00202 reportsaliases · Equation
2
Reports
5
Techniques
3
Tactics
0
Countries
20%
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1593.003 (Code Repositories), T1213.003 (Code Repositories).
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Hunt coverage 20% of 5 observed techniques (4 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
DecliningLast 30d: 0 vs 1 prior (-100%)· first reported 2026-07-21 · last 2026-08-06
0
7d
0
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months
Vulnerabilities in this actor's reporting · 5
- CVE-2017-0199KEV1 rpt
- CVE-2017-11882KEV1 rpt
- CVE-2018-0802KEV1 rpt
- CVE-2023-36884KEV1 rpt
- CVE-2026-21513KEV1 rpt
Overview
Analyst triage
Intelligence summary
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives. (Citation: Kaspersky Equation QA)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1588.006 · Vulnerabilitiesconf 652
- T1593.003 · Code Repositoriesconf 601
- T1213.003 · Code Repositoriesconf 601
- AML.T0016.002 · Generative AIconf 601
- AML.T0095.000 · Code Repositoriesconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|