Security News > 2021 > March > Chinese Hackers Stole an NSA Windows Exploit in 2014

Chinese Hackers Stole an NSA Windows Exploit in 2014
2021-03-04 12:25

Check Point has evidence that Chinese hackers stole and cloned an NSA Windows hacking tool years before Russian hackers stole and then published the same tool.

2013: NSA's Equation Group developed a set of exploits including one called EpMe that elevates one's privileges on a vulnerable Windows system to system-administrator level, granting full control.

2014-2015: China's hacking team code-named APT31, aka Zirconium, developed Jian by, one way or another, cloning EpMe.

Early 2017: The Equation Group's tools were teased and then leaked online by a team calling itself the Shadow Brokers.

Around that time, Microsoft cancelled its February Patch Tuesday, identified the vulnerability exploited by EpMe, and fixed it in a bumper March update.

Mid 2017: Microsoft quietly fixed the vulnerability exploited by the leaked EpMo exploit.


News URL

https://www.schneier.com/blog/archives/2021/03/chinese-hackers-stole-an-nsa-windows-exploit-in-2014.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
NSA 2 0 2 7 5 14