HomeAtlasDashboardChartsReal valueResearchPersonsCatalogsBlockchainBubble MapGlobeQuantumAILeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

The Shadow Brokers (2016-17): leaked NSA cyber-weapons become global ransomware

An entity calling itself The Shadow Brokers auctioned, then dumped, a cache of offensive tools attributed to the NSA-linked Equation Group (Tailored Access Operations). The April 2017 "Lost in Translation" dump included EternalBlue (an SMBv1 remote-code-execution exploit) + the DoublePulsar implant. Microsoft had quietly patched it (MS17-010, Mar 2017) a month before.

Within weeks EternalBlue powered two of the most damaging worms in history:

Honest limits. The outbreak attributions are official government attributions (high-confidence, still assertions). The identity of the Shadow Brokers themselves is unresolved - Russia widely suspected, an insider theory floated, neither proven. The enduring lesson: state-hoarded offensive tools leak and boomerang - the core case against vulnerability stockpiling and for coordinated disclosure.

Sources: Microsoft MS17-010; US-CERT; US/UK attributions (2017/2018); vendor analyses. Cross-refs: Equation_Group, NSA, North_Korea, Lazarus_Group, Russia, Malware_Lineage.

← Research index · structured data: spec-shadow-brokers-eternalblue.json · spec-shadow-brokers-eternalblue.md