
2017 NSA Leak Still Builds a Working Kill Chain in 2024
Twenty files anchored by EternalBlue, DoublePulsar, and DarkPulsar — all pulled from the 2017 ShadowBrokers dump — detect at 46 to 65 of 75-to-77 engines yet still function as a complete attack chain. The kit pairs decade-old, heavily signatured exploit code with an off-the-shelf port scanner and a single command-and-control domain that didn't exist until 2024.
Twenty files anchor this record, and on paper they should belong in a digital history archive rather than a live detection feed: EternalBlue exploitation code, the DoublePulsar kernel implant, and its sturdier successor DarkPulsar, all pulled from the Equation Group toolkit that the ShadowBrokers dumped onto the public internet in April 2017. These are not forensic curiosities sitting dormant in a vendor's sample library.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read