Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Nazar is a historical malware cluster linked to Iran in public threat research. Its connection to the NSA comes from an indicator associated with Nazar appearing in leaked Equation Group material—not from a public NSA account confirming that the agency tracked the operation. Researchers describe a modular Windows toolkit with surveillance functions, but public evidence does not establish the full victim list, definitive operator, or whether Nazar remains active.

What was the Nazar APT?

Nazar is the name used for a malware cluster described in technical analyses and a threat-group profile. The Electronic Transactions Development Agency (ETDA) lists it as “Nazar (Epic Turla),” gives SIG37 (NSA) as another name, associates it with Iran, and records information theft and espionage as its motivation. ETDA lists 2008 as its first-seen year; its card was last changed on March 13, 2024. ETDA’s threat-group card is a summary classification, not proof of a definitive operator identity.

“Iran-linked” is therefore the careful description: it reflects the public classification, while the available material does not conclusively identify who operated Nazar or establish the government’s role, if any.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did researchers connect Nazar to the NSA?

The connection is based on leaked Equation Group material titled Territorial Dispute. Check Point Research reported that material associated with SIG37 searched for the file Godown.dll; security researcher Juan Andres Guerrero-Saade connected that indicator to Nazar in his EpicTurla analysis. Check Point’s technical analysis of Territorial Dispute describes the associated detection material and execution flow.

#1 Best Overall

This supports the narrower conclusion that a Nazar-linked indicator appeared in NSA-associated detection material. It does not show exactly when or how the NSA learned of Nazar, or establish the operation’s full history. Guerrero-Saade wrote that the operation “found its way onto the NSA’s radar pre-2013,” while treating the reason for that visibility as uncertain. The phrase “monitored by NSA” should be understood as a summary of researchers’ interpretation of the leaked material, not as an NSA-confirmed description of a surveillance program.

When was Nazar active?

Public estimates differ, so 2008 is best treated as an early reported date rather than a precisely established start. ETDA records 2008 as first seen. EpicTurla says activity may reach back to 2008 but was more likely centered on 2010–2013; it also notes that possible timestamp manipulation complicates dating. Check Point’s analyzed samples indicate activity from around 2008 through at least 2012, with its latest analyzed sample dated 2012.

These are different kinds of evidence: a threat-group card’s first-seen entry, an analyst’s estimate of an activity period, and dates inferred from analyzed samples. They do not establish a single, definitive operational timeline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the Nazar malware do?

Researchers describe Nazar as a modular Windows toolkit. In the reported execution flow, a dropper installs files and registers components, while an EYService service coordinates modules. The analyzed backdoor receives UDP packets on port 1234. Reported capabilities include:

  • Keylogging and microphone recording.
  • Taking screenshots and enumerating the file system.
  • Shutting down the system.
  • Sniffing network packets.

The technical reports document capabilities in analyzed samples; they do not establish that every capability was used against every victim.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who did Nazar target, and is it still active?

The public sources do not provide a validated victim count, a complete target list, or enough victimology to define Nazar’s scope. EpicTurla notes that endpoint visibility or command-and-control sinkholing could help clarify victimology. It raises a possible overlap between machines in Iran and Equation Group implants as one explanation for NSA visibility, but explicitly presents that idea with low confidence. It is not evidence of a confirmed target set or of Iranian internal surveillance.

The reviewed historical profiles and technical analyses also do not establish whether Nazar remains active today. They describe older samples and detection material, not the operation’s current status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.