The Shadow Brokers is a threat actor known for leaking NSA-linked zero-day exploits and hacking tools since 2016.
Analyst brief
The Shadow Brokers (TSB) is a threat actor that emerged in 2016, notorious for leaking NSA-linked hacking tools and zero-day exploits. They targeted enterprise firewalls, antivirus software, and Microsoft products, indirectly impacting government entities, defense contractors, and critical infrastructure by exposing weaponized exploits. Key TTPs include the dissemination of zero-days like EternalBlue and EternalRomance, along with tools attributed to the Equation Group. Defenders must prioritize patching SMB vulnerabilities, enforcing strict network segmentation, and monitoring for any usage of these publicly leaked NSA-grade tools.
The Shadow Brokers
The ShadowBrokersTSBShadow Brokers
unknown
The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Security Agency (NSA, including several zero-day exploits.[1] Specifically, these exploits and vulnerabilities targeted enterprise firewalls, antivirus software, and Microsoft products. The Shadow Brokers originally attributed the leaks to the Equation Group threat actor, who have been tied to the NSA's Tailored Access Operations unit.