Researchers at Check Point Research revealed conclusive evidence that APT31 (Zirconium) obtained and repurposed an NSA Equation Group exploit years before it became publicly available through the Shadow Brokers leak — creating a Windows Local Privilege Escalation (LPE) exploit dubbed "Jian" from the Equation Group's "EpMe" tool, and deploying it against targets including what appears to be a U.S. defense contractor.
Key Findings
The exploit CVE-2017-0005 — attributed by Microsoft to APT31 — is, in fact, a replica of the Equation Group's EpMe exploit, which targets the same Windows LPE vulnerability and was part of the DanderSpritz attack framework, dated to at least 2013. APT31 had access to EpMe's actual binary files — both 32-bit and 64-bit versions — more than two years before the Shadow Brokers' "Lost in Translation" leak made them publicly available. The replica, Jian, was compiled in October 2014 and used in attacks from at least 2015 until Microsoft patched the vulnerability in March 2017 — after CVE-2017-0005 was reported to Microsoft by Lockheed Martin's Computer Incident Response Team, strongly suggesting the exploit was caught targeting a U.S. defense-sector organization.
Anatomy of the Exploit Chain
Jian is shipped as a DLL named Add.dll with a single exported function AddByGod — the packer entry point. The four-stage loading sequence proceeds as follows: the packer allocates memory, derives an AES-256 decryption key via SHA-1 from a password argument, decrypts the second-stage shellcode, which then decompresses and loads a third-stage PE with intentionally corrupted headers. The third stage reflectively loads a fourth embedded PE — the exploit itself — compiled in October 2014. The same packer architecture, function naming convention, and PDB path pattern was also identified in CVE-2019-0803, separately attributed to Chinese state-sponsored actors by the NSA, confirming a shared tooling ecosystem across multiple Chinese APT operations.
The Equation Group Connection: EpMe and EpMo
Check Point's analysis of the DanderSpritz framework — the Equation Group toolset that contained EpMe — identified four Windows LPE exploits total. One of these, code-named EpMo, had never been publicly discussed before this research. EpMo was quietly patched by Microsoft in May 2017 with no assigned CVE-ID, apparently as a follow-on response to the Shadow Brokers leak — making this research the first public documentation of this additional Equation Group vulnerability's existence.
The technical signature connecting Jian to EpMe is definitive: Jian's rich OS version context structure, global configuration table architecture, and specific field layouts match the Equation Group framework's internal patterns — artifacts that go far beyond coincidence and demonstrate APT31 had direct access to the Equation Group source files or binaries, not merely observed the exploit in network traffic (as was assessed for APT3's acquisition of EternalRomance in the Bemstour case).
Implications: Nation-State Cyber Weapon Proliferation
The Jian case establishes a documented instance of Chinese intelligence stealing U.S. cyber weapons and repurposing them against American targets — a scenario with implications that parallel physical weapons theft in their strategic significance, but which unfolds invisibly due to the digital and volatile nature of cyber tools. Unlike the Shadow Brokers leak, which publicized NSA capabilities globally, APT31's quiet acquisition and exploitation of EpMe went undetected for years. The case underscores the risk that nation-state-grade offensive tools represent not just in the hands of their developers, but as proliferation risks that can be captured and weaponized by sophisticated adversaries.