Equation Group is a highly sophisticated threat actor, exposed by Kaspersky in 2015 and widely assessed as NSA-linked, whose MENA relevance stems from Stuxnet-class sabotage of Iran's Natanz nuclear program and espionage victims across the Middle East using zero-day exploits and hard-drive firmware implants.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Kaspersky detailed Equation Group in February 2015 as one of the most advanced actors ever observed, active since at least 2001. MITRE tracks it as G0020. Public and journalistic reporting widely assess it as linked to the U.S. National Security Agency and as sharing the 'Tilded' development platform with the operators of Stuxnet and Duqu; attribution to a specific service remains officially unconfirmed, so the sponsor assessment is high confidence on capability but circumstantial on the exact agency — a nuance preserved here.
The group's tradecraft is exceptional: zero-day exploitation, interdiction of physical media, self-propagating tools (Fanny), and the hallmark ability to reprogram hard-drive firmware (EquationDrug, GrayFish) for persistence surviving reinstalls. MITRE maps it to peripheral/component firmware manipulation, execution guardrails, and hidden file systems. Its most consequential MENA operation is the Stuxnet worm, which sabotaged uranium-enrichment centrifuges at Iran's Natanz facility (discovered 2010) — a defining act of state destructive cyber operations against a MENA target.
MENA victimology, per Kaspersky, included thousands of infections concentrated in Iran, alongside victims in other Middle Eastern and North African states (and globally), spanning government, telecom, energy, nuclear-research, and military/aerospace targets. The Iran-focused espionage and the Natanz sabotage make Equation Group directly relevant to a MENA-targeting roster despite its Western attribution.
Equation Group activity under this name effectively ceased public visibility after the 2015 exposure and the 2016-2017 Shadow Brokers leaks of its tooling; it is assessed as dormant under this designation. It is included as an attribution-sensitive but citable non-Iran-nexus MENA-targeting historical entry.