Chinese Cybersecurity Team Discloses Details of Backdoor Tool of U.S. NSA Equation Group

The backdoor codenamed Bvp47, also named “Operation Telescreen” by Pangu Lab, is said to have infiltrated 287 targets in 45 countries and regions including Russia, Japan, Spain and Italy, working as a monitoring tool.

Image Source: Visual China

Image Source: Visual China

BEIJING, February 23 (TMTPOST) — Pangu Lab, a Chinese research team specializing in cybersecurity, discloses details of a top-tier backdoor hacking tool of the United States National Security Agency (NSA) Equation Group in a blog post on its official site.

The backdoor codenamed Bvp47, also named “Operation Telescreen” by Pangu Lab, is said to have infiltrated 287 targets in 45 countries and regions including Russia, Japan, Spain and Italy, working as a monitoring tool. The attack from Operation Telescreen has lasted for over a decade, according to Pangu Lab’s blog post. One victim of the cyberattack operation is used as a jump server for further attack, Pangu Lab said.

“The tool is well-designed, powerful, and widely adapted. Its network attack capability equipped by 0day vulnerabilities was unstoppable, and its data acquisition under covert control was with little effort,” Pangu Lab said. “The Equation Group is in a dominant position in nation-level cyberspace confrontation.”

The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the Tailored Access Operations (TAO) unit of the United States National Security Agency.

Pangu Lab extracted a set of advanced backdoors during an in-depth forensic investigation of a host in a key domestic department in 2013, from which the lab uncovered Bvp47. The lab cracked the check code to the backdoor and tested the backdoor’s behaviors. The lab concluded that it is a top-tier APT backdoor.

Image Source: Pangfu Lab

Image Source: Pangu Lab

Pangu Lab’s founder Han Zhengguang said that Telescreen Operation is a top-notch backdoor program that allows the Equation Group to move around and acquire information in cyberspace freely.

Telescreen Operation can attack operating systems such as most Linux versions, AIX, Solaris and SUN. It exhibited an advanced level of code obfuscation, system hiding, and self-destruction design, according to Pangu Lab. The backdoor might have existed for nearly 20 years.

Pangu Lab is owned by cybersecurity service provider Qi An Xin Technology (SHA: 688561), which has close connection with software company Qihoo 360. Qihoo 360 sold a 22.59% stake to China Electronics Corporation in April 2019.

本文系作者 Garrett_Li 授权钛媒体发表,并经钛媒体编辑,转载请注明出处、作者和本文链接
本内容来源于钛媒体钛度号,文章内容仅供参考、交流、学习,不构成投资建议。
想和千万钛媒体用户分享你的新奇观点和发现,点击这里投稿 。创业或融资寻求报道,点击这里

敬原创,有钛度,得赞赏

赞赏支持
发表评论
0 / 300

根据《网络安全法》实名制要求,请绑定手机号后发表评论

登录后输入评论内容

快报

更多

2025-05-22 23:14

中国联通领导班子调整:唐永博接替王俊治任党组副书记

2025-05-22 23:13

金砖国家新开发银行扩员,阿尔及利亚成为新成员国

2025-05-22 23:07

卧龙新能:拟出售卧龙矿业90%股权,构成重大资产重组

2025-05-22 23:02

美联储沃勒:仍然认为关税将是一次性的价格上涨

2025-05-22 22:42

美国天然气期货日内下跌3%,现报3.27美元/百万英热

2025-05-22 22:34

英国宣布将查戈斯群岛主权移交给毛里求斯

2025-05-22 22:31

美国至5月16日当周EIA天然气库存1200亿立方英尺

2025-05-22 22:30

何立峰会见美国摩根大通集团董事长兼首席执行官杰米·戴蒙时指出,中国欢迎美资企业深化对华互利合作,推动中美经贸关系健康稳定持续发展

2025-05-22 22:25

现货钯金跌破1000美元

2025-05-22 22:13

OpenAI宣布“星际之门”首个国际部署项目落户阿联酋,并考虑扩张至亚太地区

2025-05-22 22:01

美国4月成屋销售总数年化400万户,创2009年以来同期最差

2025-05-22 21:53

苹果、特斯拉和英伟达等热门股票将在加密货币交易所Kraken以数字代币形式交易

2025-05-22 21:46

美国5月标普全球服务业PMI初值为52.3

2025-05-22 21:45

北京乐自天成文化发展股份有限公司向港交所提交上市申请书

2025-05-22 21:35

ST汇金:5月26日起撤销其他风险警示,证券简称变更为“汇金股份”

2025-05-22 21:31

美股开盘:三大指数涨跌不一,加密货币概念股普涨

2025-05-22 21:29

摩根大通首席执行官到访北京

2025-05-22 21:15

雷军谈小米YU7定价:19万9是不可能的,将于今年7月正式上市

2025-05-22 21:02

国内期货夜盘开盘多数下跌,沪金跌0.53%

2025-05-22 21:02

5月22日新闻联播速览24条

扫描下载App