APTMembers
APT

2017 NSA Leak Still Builds a Working Kill Chain in 2024

Twenty files anchored by EternalBlue, DoublePulsar, and DarkPulsar — all pulled from the 2017 ShadowBrokers dump — detect at 46 to 65 of 75-to-77 engines yet still function as a complete attack chain. The kit pairs decade-old, heavily signatured exploit code with an off-the-shelf port scanner and a single command-and-control domain that didn't exist until 2024.

Oct 1, 2026, 14:27 (UTC+9)Last seenOct 1, 2026Severity77ByCTX TeamActorRaspiteLeafminerIOC53MITRE59RegionsUS

Twenty files anchor this record, and on paper they should belong in a digital history archive rather than a live detection feed: EternalBlue exploitation code, the DoublePulsar kernel implant, and its sturdier successor DarkPulsar, all pulled from the Equation Group toolkit that the ShadowBrokers dumped onto the public internet in April 2017. These are not forensic curiosities sitting dormant in a vendor's sample library.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence