Kaspersky has managed to identify after two years an APT group, which was mentioned in the Shadow Brokers in 2017.
In 2017, a hacking group known as the Shadow Brokers published a data dump called “Lost in Translation”.
The data dump contained various exploits and hacking tools that the hackers had stolen from the NSA. One of the most well-known exploits published was EternalBlue , which was used for the WannaCry , NotPetya, and Bad Rabbit ransomware attacks in the devastating 2017 attacks
The "data dump" also contained a file named sigs.py.
NSA hackers used this file as a malware scanner to scan the computers they infected. Essentially, they scanned the computers for other APTs (a term usually used to describe state-sponsored hacking groups).
The sigs.py script was able to detect 44 other APTs. Many of these groups were unknown to the cybersecurity industry in 2017 (when the leak occurred). This means that the NSA had a significant tool in its hands, capable of detecting and monitoring the activities of many dangerous APT groups.
However, Kaspersky published a report, in which it says it managed to identify one of the mysterious APT groups.
The researchers named the group "DarkUniverse" and stated that the hackers were active from 2009 to 2017. After the ShadowBrokers leak, their trail was lost.
“Their suspension of activities may be related to the publication of 'Lost in Translation'. They may also have decided to switch to more modern approaches,” Kaspersky said.

20 victims in Africa, Europe and the Middle East
Kaspersky said it found 20 victims of this APT group, who came from Russia, Belarus, Syria, Iran, Afghanistan, Ethiopia, Sudan, Tanzania and the United Arab Emirates.
The victims were, mainly, political and military organizations, medical institutions, atomic energy agencies and telecommunications companies.
However, Kaspersky experts are confident that the actual number of victims is much higher.
Regarding the DarkUniverse malware framework, researchers found code overlap with the ItaDuke/APT malware , which has been used to attack Uyghur and Tibetan minorities.
However, it is not certain whether the DarkUniverse malware originated from Chinese hackers. More information is needed.
According to Kaspersky researchers, the DarkUniverse malware framework is a typical remote access, but it is particularly advanced and dangerous. In the image below you can see its capabilities.

