Longhorn, also known as The Lamberts, is a highly sophisticated cyber-espionage threat actor and malware ecosystem publicly associated with U.S. intelligence operations, with reporting linking it to the CIA. The actor has been active since at least 2008 and is known for a mature, multi-family toolkit used against high-profile targets, particularly in Europe, with observed activity concentrated in 2013 and 2014 and related tooling still seen through 2016. The Longhorn arsenal includes active and passive backdoors, modular implants, harvesting tools, and wipers across Windows and OS X. Publicly documented families include Black Lambert, White Lambert, Blue Lambert, Green Lambert, Pink Lambert, and Gray Lambert. Black Lambert functioned as an active implant and was notably deployed in a 2014 intrusion that exploited CVE-2014-4148 against a high-profile European organization. White Lambert and Gray Lambert were passive network-driven backdoors designed to intercept specially crafted network traffic for covert tasking, with White Lambert operating in kernel mode and Gray Lambert representing a later user-mode evolution. Blue Lambert and Green Lambert were related active implant families, while Pink Lambert included beaconing, USB-harvesting, and orchestration components. The toolkit demonstrates advanced tradecraft including kernel-mode traffic interception, covert network-driven command execution, in-memory plugin execution, timestamp tampering, modular staging, and abuse of signed drivers to load unsigned code on 64-bit Windows. Shared code, data formats, infrastructure patterns, and victim overlap link the Lambert families into a single operational ecosystem. The overall sophistication of Longhorn has been compared with top-tier espionage platforms such as Regin, ProjectSauron, Equation, and Duqu2. Longhorn is assessed as an espionage actor focused on stealthy long-term access to high-value targets rather than financially motivated operations. Known aliases include The Lamberts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a separate U.S.-attributed intrusion collective for comparison/background, not as the main subject of the Bvp47 reporting.
Referenced as a cyber-espionage group linked to Vault 7 tooling; the post notes Kaspersky correlated Lamberts with Longhorn.
Highly sophisticated cyber espionage threat actor operating since at least 2008, using multiple modular backdoors, passive network implants, USB-harvesting tools, orchestrators, and wipers across Windows and OS X. The group deployed BlackLambert via the CVE-2014-4148 zero-day and operated several related malware families including Black, White, Blue, Green, Pink, and Gray Lambert.
Highly sophisticated cyber-espionage activity cluster associated with the multi-stage 'Lamberts' toolkit (multiple generations of active and passive implants/backdoors, modular tooling, USB harvesting, and wiper capability), observed since at least 2008 and publicly surfaced in 2014 via a TTF zero-day exploit chain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.