A malware sample found by ESET combined a packer linked to the Chinese hacking group Winnti with PeddleCheap, an implant attributed to Equation Group, which is broadly believed to have ties to the U.S. National Security Agency (NSA). But the sample’s appearance does not prove who assembled it—or that it was used in an attack. ESET and CyberScoop described competing explanations, with Winnti’s reuse of leaked tools considered the likeliest.
What did ESET find?
In a report published May 7, 2020, CyberScoop described an ESET discovery: a sample that brought together two code components associated with different actors. One was a packer, a tool that can obscure or package malware, linked to Winnti. The other was PeddleCheap, an implant attributed to Equation Group, a hacking faction broadly believed to have ties to the NSA. CyberScoop’s report says the sample was uploaded to VirusTotal in 2017, according to ESET researcher Marc-Étienne Léveillé.
ESET’s Q2 2020 Threat Report adds that the samples launched PeddleCheap while installing a legitimate copy of Adobe Flash Player. ESET said the malware was embedded with a packer known to be used only by Winnti, while noting that the context around the samples was unclear. ESET’s report describes the combination.
What is PeddleCheap, and how did it become public?
PeddleCheap is the implant in the sample that ESET attributed to Equation Group. It appeared in an April 2017 leak by the Shadow Brokers, a group that publicly released tools associated with Equation Group. That public exposure provides a plausible route for other parties to obtain and reuse the code; it does not establish how the particular sample was assembled.
#1 Best Overall
Who might have assembled the sample?
ESET and CyberScoop did not determine whether the sample was used in a real malicious campaign or assembled by a researcher experimenting with available tools. Léveillé considered three explanations, ranked by likelihood:
- Winnti reused leaked tools. The likeliest explanation, in Léveillé’s assessment, is that Winnti used tools from the Shadow Brokers leak as a first stage in compromising victims in 2017. The packer’s link to Winnti and the public availability of PeddleCheap make this a possible account, but the sample alone does not prove it.
- Equation Group reused Winnti’s packer. Léveillé described this as less likely: Equation Group may have encountered and reused a packer associated with Winnti. The sample does not establish that this happened.
- A third party combined the tools. A party with access to the Winnti-linked packer could have paired it with PeddleCheap from the leak. Léveillé considered this even less likely, but it remains an alternative.
These are hypotheses, not confirmed chains of custody. The strongest component-level clues—PeddleCheap’s attribution and the packer’s Winnti link—do not independently identify who put them together or why.
Did Chinese hackers steal NSA malware?
This sample does not prove that they did. It shows a Winnti-linked packer alongside an implant attributed to Equation Group; because PeddleCheap had appeared in a public leak, reuse is one explanation. The available reporting does not establish that Winnti stole the implant from the NSA, that the NSA created or operated this exact sample, or that either group deployed it against a known victim.
There is a separate historical detail that can add to the confusion: CyberScoop reported that Chinese hackers known as Buckeye or APT3 had access to some tools that later appeared in the Shadow Brokers leak, months before that public disclosure. It remained unclear whether they breached NSA systems, encountered the tools in use, or independently observed the same vulnerabilities and developed similar exploit tools. That separate account does not establish who assembled the ESET sample.
Recommended Free Tools
Can malware code prove who conducted an intrusion?
Code can provide clues about a tool’s history or associations, but it is not proof of the operator behind a particular incident. Once code or a tool is leaked, documented, or otherwise obtained, another party can reuse it. An analyst who sees a familiar component may therefore identify a connection to an earlier tool without proving who deployed it in a given case.
Léveillé’s point to CyberScoop was that samples like this show why attribution is difficult, sometimes impossible, when analysts look only at malware without additional context. In this case, the component overlap is real, but the available sources provide no confirmed campaign, victim, or operational context that settles authorship.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

