/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Check Point: Chinese hacker group APT3 reverse engineered EternalRomance NSA exploit by setting up machines as traps to retrieve info after they were attacked

I write about security and surveillance.  —  When it was alleged earlier this year that secretive Chinese hacking group APT3 … Tweets: @_cpresearch_ , @docligot , @hatr , and @virusbtn Tweets: @_cpresearch_ : Earlier this year Symantec revealed that APT3 was using NSA-like exploits in 2016, before The Shadow Brokers' leak. Our researchers took a technical deep dive to the Chinese exploits to explain how that might have happened. https://research.checkpoint.com/ ... Dominic Ligot / @docligot : Check Point's research team believes the Chinese set deliberate traps to capture American cyber weapons, they were not discovered and seized by accident. https://www.forbes.com/... @hatr : “Our observations from the technical analysis allow us to provide evidence ... APT3 recreated its own version of an Equation group exploit using captured network traffic.” Spies watching spies, forever fascinating https://research.checkpoint.com/ ... via @craiu Virus Bulletin / @virusbtn : Check Point researchers analysed the Chinese use of some NSA tools prior to their leakage and suspect they may have been caught through the use of a honeypot https://research.checkpoint.com/ ... https://twitter.com/...

Forbes Zak Doffman

Context & Ripple Effects

Earlier this year Symantec reported that APT3 was using NSA-grade exploits back in 2016 — before the Shadow Brokers leak could have handed them over. Check Point's research team supplies the missing mechanism: the Chinese group ran deliberate trap machines that let themselves get attacked so they could harvest the incoming traffic and reconstruct the weapon, in this case EternalRomance.

The finding reframes an already-familiar story. The leaked NSA toolkit had already become commodity malware once public — the EternalBlue exploit became a go-to hacker tool within a year of leaking — but this shows adversaries didn't need the leak at all to acquire the same capabilities.

First-order effects

  • Defenders and threat-intelligence teams lose a key attribution anchor: exploits previously assumed to post-date the Shadow Brokers leak were demonstrably in APT3's hands years earlier, so 'leaked NSA code' is no longer reliable evidence of when or how an adversary obtained it.

Second-order effects

  • Other state hacking programs now have a proven playbook for acquiring rival arsenals without waiting for leaks — honeypot-style capture turns every target network into potential reconnaissance on an opponent's tradecraft, raising the cost calculus for agencies like the NSA deploying offensive tools in the field.

Third-order effects

  • Offensive cyber weapons behave as inherently leaky dual-use assets: whether through dumps like Shadow Brokers or field capture like APT3's traps, an exploit built by one government tends to end up in many hands — which strengthens the case, echoed in China's own evolving state-hacking model, that stockpiled vulnerabilities are liabilities as much as assets.

The trend: State-built cyber weapons are diffusing faster than their creators can control them, with adversaries increasingly able to reconstruct classified toolkits from field operations rather than leaks alone.

Discussion

  • @_cpresearch_ @_cpresearch_ on x
    Earlier this year Symantec revealed that APT3 was using NSA-like exploits in 2016, before The Shadow Brokers' leak. Our researchers took a technical deep dive to the Chinese exploits to explain how that might have happened. https://research.checkpoint.com/ ...
  • @docligot Dominic Ligot on x
    Check Point's research team believes the Chinese set deliberate traps to capture American cyber weapons, they were not discovered and seized by accident. https://www.forbes.com/...
  • @hatr @hatr on x
    “Our observations from the technical analysis allow us to provide evidence ... APT3 recreated its own version of an Equation group exploit using captured network traffic.” Spies watching spies, forever fascinating https://research.checkpoint.com/ ... via @craiu
  • @virusbtn Virus Bulletin on x
    Check Point researchers analysed the Chinese use of some NSA tools prior to their leakage and suspect they may have been caught through the use of a honeypot https://research.checkpoint.com/ ... https://twitter.com/...