Lamberts, also known as Longhorn and tracked by some researchers as Bright Constellation, is a highly sophisticated cyberespionage threat actor widely linked in public reporting to the U.S. Central Intelligence Agency. The group is known for an extensive and diverse malware ecosystem that includes multiple color-coded and otherwise distinct families such as Gray Lambert, Red Lambert, Brown Lambert, SilverLambert, ColoredLambert, Rationalist, Marianas Trench, Invisible Enemy, Bloodletter, Existence, Escape Artist, Cutting Ties, Level, and Impairment. Public research has characterized the actor as an apex-tier operator with a large arsenal spanning passive network-driven backdoors, modular implants, harvesting tools, and destructive capabilities including wipers. The actor’s tradecraft emphasizes stealth, persistence, and long-term intelligence collection against strategic targets. Lamberts tooling has included passive “NOBUS”-style implants designed to receive covert tasking without relying solely on conventional outbound command-and-control patterns. Gray Lambert in particular has been described as a user-land passive implant capable of orchestrating multiple sniffer victims through broadcast, multicast, and unicast communications. Researchers have also noted similarities between Lambert tradecraft and other elite passive persistence approaches. Across analyzed samples, the malware frequently appears engineered to run as Windows services and to evade scrutiny by experienced administrators and Windows logging or telemetry rather than relying heavily on user-lure themes or overt antivirus bypass. The group has demonstrated cross-platform capability. SilverLambert samples have been compiled for both Windows and Linux, and the broader Lambert toolkit includes several generations of modular backdoors and network-aware implants. Associated malware such as ColoredLambert has been observed in victim environments alongside other advanced frameworks, reinforcing the assessment that the actor conducts complex, multi-stage intrusion operations. Public reporting also links the group to destructive attack capability through the inclusion of wipers in its arsenal. Victimology indicates a focus on strategic verticals in Asia and the Middle East. Gray Lambert activity has been specifically associated with strategic targets in those regions. The actor is assessed as espionage-motivated, consistent with its malware design, operational sophistication, and targeting profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point among publicly discussed Western government hacking groups.
A highly regarded threat actor discussed through analysis of its multi-framework malware toolkit. The content focuses on clustering and linking multiple malware families attributed to the actor using YARA-based similarity methods.
Highly sophisticated actor with a large malware arsenal including Linux-compiled SilverLambert and cross-platform Green Lambert variants.
A cyberespionage group referenced because its ColoredLambert malware was found on some of the same computers as DePriMon within a short time frame.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.