DoublePulsar
Backdoor implant tool
DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agency's (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017. The tool infected more than 200,000 Microsoft Windows computers in only a few weeks, and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack.
Nº Q29971716 ★
Common · Literature
DoublePulsar
Backdoor implant tool
DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agency's (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017. The tool infected more than 200,000 Microsoft Windows computers in only a few weeks, and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack.
From Wikipedia
DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agency's (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017. The tool infected more than 200,000 Microsoft Windows computers in only a few weeks, and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack. A variant of DoublePulsar was first seen in the wild in March 2016, as discovered by Symantec. Sean Dillon, senior analyst of security company RiskSense Inc., first dissected and inspected DoublePulsar. He said that the NSA exploits are "10 times worse" than the Heartbleed security bug, and use DoublePulsar as the primary payload. DoublePulsar runs in kernel mode, which grants cybercriminals a high level of control over the computer system. Once installed, it uses three commands: ping, kill, and exec, the latter of which can be used to load malware onto the system.
Text: Wikipédia, CC BY-SA 4.0. · Image: NSA (Public domain) ·
Related cards
-
W
WannaCry ransomware attack
Ransomware cyberattack
Nº Q29957041 ★★★
Not listed
-
WannaCry
Ransomware
Nº Q29908721 ★★★
Not listed
-
E
EternalBlue
Computer security exploit
Nº Q29916946 ★★
Not listed
-
The Shadow Brokers
Computer hacker group that released sensitive NSA data
Nº Q27134643 ★★
Not listed
-
M
Malicious Software Removal Tool
Freely distributed virus removal tool developed by Microsoft for the Microsoft Windows operating system
Nº Q1259297 ★
Not listed
-
Bullrun (decryption program)
Code name of a decryption program run by the NSA.
Nº Q14831675 ★
Not listed