Security News > 2021 > February > Chinese Hackers Hijacked NSA-Linked Hacking Tool: Report

New research has found evidence that a Chinese-affiliated threat group has hijacked a hacking tool previously used by the Equation Group.
"Although we don't show any conclusive evidence that there is there any connection between China and the ShadowBrokers, we do show conclusive evidence that this Chinese group had in their possession a tool that was made by Equation Group, and not only that they had this tool, but they also repurposed it and used it, probably to attack many targets, including American targets," Yaniv Balmas, head of cyber research with Check Point Software, said.
Although we don't show any conclusive evidence that you know, there is there any connection between China and the Shadow Brokers we do show conclusive evidence that this Chinese group had in their possession, a tool that was made by Equation Group, and not only that they had this tool, but they also repurposed it and used it, probably to attack many targets, including American targets.
So the ones that remain open, and the ones that we think are most probable are: One, it is possible, for example, that the Equation Group attacked some Chinese target.
Another possible scenario is that this Chinese group hacked into the Equation Group - I think it's less probable, but still, it is a possibility.
I think the American tool seems to be much more mature, much more elegant in the way it's written.
News URL
https://threatpost.com/chinese-hackers-hijacked-nsa-hacking-tool/164155/
Related news
- Chinese Weaver Ant hackers spied on telco network for 4 years (source)
- Hackers Use .NET MAUI to Target Indian and Chinese Users with Fake Banking, Social Apps (source)
- Chinese Hackers Breach Asian Telecom, Remain Undetected for Over 4 Years (source)
- Chinese FamousSparrow hackers deploy upgraded malware in attacks (source)
- Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool (source)
- Chinese hackers target Russian govt with upgraded RAT malware (source)
- Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool (source)
- Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell (source)
- Chinese hackers behind attacks targeting SAP NetWeaver servers (source)