Green Lambert is an active implant within the Lambert, also known as Longhorn, cyber-espionage toolkit. It is assessed as an older, lighter, and more reliable counterpart to Blue Lambert and has been linked to a broader multi-family arsenal that includes Black, White, Pink, and Gray Lambert. The family has been associated with high-end espionage operations and is notable for having both Windows and macOS variants, making it the only Lambert family publicly documented across non-Windows platforms.
Green Lambert supports command-and-control communications through direct network connectivity with fallback mechanisms and proxy-aware operation. Documented discovery behavior includes collecting host date and time and identifying proxy configuration from the compromised system. On macOS, observed persistence mechanisms include LaunchAgents, LaunchDaemons, LoginItems, RC scripts, and shell configuration modification, with launchd used for execution. The malware has also been observed creating a LaunchAgent configured to run at user logon. Defense-evasion tradecraft includes masquerading as legitimate software components, custom and in-memory string decryption, and self-deletion after installation.
Green Lambert has been disguised as benign Apple- or third-party-looking components to reduce suspicion. On macOS, it has masqueraded as a Growl helper component; on Windows, it has also used legitimate-looking software-update themed naming. A documented dropper associated with the family abused an industrial control software package as a delivery vehicle, indicating selective and potentially high-value targeting. Public reporting does not establish a confirmed initial access vector for Green Lambert itself, and there is no high-confidence evidence in the available material for privilege escalation, lateral movement, or specific exfiltration behavior by this family.
The Lambert toolkit as a whole has targeted high-profile victims and is widely regarded as a top-tier espionage platform comparable in sophistication to Regin, ProjectSauron, Equation, and Duqu2. Green Lambert samples were active during the broader Lambert activity window concentrated in the early-to-mid 2010s, with related Lambert operations and migrations continuing into 2016.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Green Lambert is a lighter, more reliable, but older version of Blue Lambert... both Blue and Green are active implants.
Nevertheless, signatures that we created for Green Lambert for Windows also triggered on a macOS variant of Green Lambert that was functionally similar to the Windows version.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Green Lambert can create a Launch Agent with the RunAtLoad key-value pair set to true, ensuring the com.apple.GrowlHelper.plist file runs every time a user logs in. Komplex creates a persistent launch agent called ... com.apple.updates.plist. MacMa installs a com.apple.softwareupdate.plist file in the /LaunchAgents folder.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
"...most compilation timestamps in the PE header appear to have been tampered (to reflect a 2003-2004 range)..."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
AuditCred can utilize proxy for communications... FunnyDream can identify and use configured proxies in a compromised network for C2 communication... Kapeka can identify system proxy settings via WinHttpGetIEProxyConfigForCurrentUser() during initialization and utilize these settings for subsequent command and control operations... PoshC2 contains modules that allow for use of proxies in command and control.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obtains proxy information from victim machines via environment variables.
CIA-linked implant/backdoor with multiple macOS persistence mechanisms (LoginItem/plist modification, RC scripts, LaunchAgent/LaunchDaemon, Launchd scheduled execution, shell configuration modification), defense evasion via string decryption/obfuscation and self-deletion, masquerading as legitimate services (GrowlHelper, Software Update Check), basic host/network discovery (OS version/uptime, proxy settings, system time), and command-and-control via DNS with proxy support and hostname/IP fallback.
Lambert family backdoor referenced in discussion of cross-platform variants.
macOS malware that creates a Launch Agent configured with RunAtLoad=true to execute at user login.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.