Names | DOUBLEFANTASY DoubleFantasy VALIDATOR | |
Category | Malware | |
Type | Reconnaissance, Downloader | |
Description | (Kaspersky) The Equation Group’s DoubleFantasy implant is a validator-style Trojan which sends basic information about the system to the attackers. It also allows them to upload a more sophisticated Trojan platform, such as EQUATIONDRUG or GRAYFISH. In general, after one of these sophisticated platforms are installed, the attackers remove the DoubleFantasy implant. In case the victim doesn’t check out, for example, if they are a researcher analysing the malware, the attackers can simply choose to uninstall the DoubleFantasy implant and clean up the victim’s machine. | |
Information | <https://securelist.com/equation-group-from-houston-with-love/68877/> <https://www.antiy.com/response/FROM_EQUATION_TO_EQUATIONS.pdf> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/elf.doublefantasy> <https://malpedia.caad.fkie.fraunhofer.de/details/win.doublefantasy> |
Last change to this tool card: 28 December 2022
Download this tool card in JSON format
Changed | Name | Country | Observed | ||
APT groups | |||||
Equation Group | 2001-Aug 2016 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |