The Shadow Brokers NSA Equation Group Leak: EternalBlue, EternalRomance, DoublePulsar, and the Fuzzbunch Framework Released April 2017

Rapid7 published a technical FAQ on Rapid7 analyzing the April 15, 2017 Shadow Brokers release — a trove of alleged NSA Equation Group tools including Windows exploitation framework Fuzzbunch, multiple SMB exploit modules, and post-exploitation tools. The Shadow Brokers first emerged in August 2016 claiming to possess Equation Group firewall implants and exploitation scripts targeting Cisco, Juniper, and Topsec (subsequently confirmed and patched), before releasing the April 2017 password for their encrypted archive after failing to sell the contents for their demanded price (initially 1 million bitcoins, later 10,000).

Released Exploit Suite: EternalBlue, EternalRomance, EternalSynergy, EternalChampion, and Five Other SMB/Kerberos Modules

The April 2017 release contained eight named exploits, none of which were zero-days at time of release. All were previously patched, with four addressed the prior month in Microsoft's March 2017 updates. The EternalBlue, EternalRomance, EternalSynergy, and EternalChampion exploits (targeting CVE-2017-0143 through CVE-2017-0148, bundled under MS17-010) attack Windows SMB. EmeraldThread targets print spooler vulnerability MS10-061, EskimoRoll targets Kerberos checksum flaw MS14-068 (CVE-2014-6324), EducatedScholar targets SMBv2 MS09-050, and EclipsedWing targets the MS08-067 NetAPI vulnerability. All eight exploits can be pivoted to a Meterpreter session via the DoublePulsar kernel implant, which installs a backdoor enabling arbitrary shellcode injection into kernel memory.

Fuzzbunch: NSA's Internal Exploit Delivery Framework

The release included Fuzzbunch — the Equation Group's internal framework for loading and delivering exploit binaries onto target systems — effectively providing the broader attacker community with an operational exploit management platform comparable to commercial tools like Metasploit, but designed for the specific NSA exploit suite. The combination of Fuzzbunch and the DoublePulsar implant creates a complete attack pipeline: Fuzzbunch delivers the initial exploit, DoublePulsar installs the kernel backdoor, and subsequent payloads (including Meterpreter) are injected via the implant. The release represented the largest publicly confirmed leak of alleged nation-state offensive cyber tooling to date, and within weeks would provide the foundation for the WannaCry and NotPetya global ransomware outbreaks via the EternalBlue/DoublePulsar combination.

Read the full analysis on IntelFusions