Chinese, Russian Cyber Groups Research Shadow Brokers Malware

Cyber communities in China and Russia have started digging into the most recent release of malware from Shadow Brokers.

Kelly Sheridan, Former Senior Editor, Dark Reading

April 25, 2017

2 Min Read
Dark Reading logo in a gray background | Dark Reading

Chinese and Russian cyber communities have begun investigating malware disclosed in the April Shadow Brokers data dump, reports Recorded Future.

Earlier this month, the Shadow Brokers hacking group released a series of tools allegedly belonging to the NSA. Now foreign security researchers and cyber actors are digging into these previously undisclosed vulnerabilities and exploits, and learning how they work.

"The criminal underground has spotted a huge opportunity here to piggyback on these exploits before there's large-scale patching across the world," says Levi Gundert, VP of intelligence and strategy at Recorded Future.

Recorded Future's research indicates there is broad interest in Shadow Brokers' tools among the Chinese and Russian cyber communities. Many actors likely see potential to make a lot of money through spam, botnets, ransomware, and other new tools, he continues.

When the Shadow Brokers release was announced, researchers pulled key trends and phrases around tools specifically mentioned in dark web forms and monitored their activity. They noticed communities were particularly interested in the exploit framework, SMB malware, and the privilege escalation tool.

Specifically, Chinese actors are looking into unique malware triggers. Many seem to think the underlying vulnerability exploited by these tools has not been fully patched. What's more, Chinese APT groups have shown they can quickly weaponize zero-day vulnerabilities -- another sign that threat actors from the country may reuse the Shadow Brokers malware.

"This is really a feeding frenzy for the criminal community," Gundert says of the Shadow Brokers leak. "It's like Christmas has come early for them."

He anticipates we'll see an increase in chatter throughout these communities, and growth of exploitation and monetization as cybercriminals pursue opportunities to improve their hacking techniques based on higher-level toolsets. It's clear they come from an advanced group.

"These are very sophisticated tools and techniques, generally above the reach of the criminal underground community," he explains.

For businesses trying to protect themselves, Gundert recommends understanding what these exploits are, and ensuring there is a vulnerability management program in place.

About the Author

Kelly Sheridan

Former Senior Editor, Dark Reading

Kelly Sheridan was formerly a Staff Editor at Dark Reading, where she focused on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial services. Sheridan earned her BA in English at Villanova University. You can follow her on Twitter @kellymsheridan.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights