Netskope Threat Labs

ShadowBrokers

ATP Sandbox Adv. HeuristicsAV

ShadowBrokers is a group that leaked troves of exploitation tools and vulnerabilities stolen from the United States National Security Agency, starting in 2016. The leaked tooling included EternalBlue and other exploits that later powered destructive worms such as WannaCry and NotPetya.

First seen
February 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Exploit.ShadowBrokers
Gen:Variant.ShadowBrokers.1
Generic.Backdoor.ShadowBrokers.07B3E2B2
Generic.Backdoor.ShadowBrokers.93283F2A
Generic.Backdoor.ShadowBrokers.A3B68A18
Generic.Backdoor.ShadowBrokers.E9302484
Script-Python.Exploit.ShadowBrokers
Trojan.ShadowBrokers.A
Win32.Exploit.ShadowBrokers