White Lambert is a sophisticated passive backdoor within the Lambert, or Longhorn, cyber-espionage toolkit. It is designed for covert, network-driven command execution rather than conventional beaconing: the implant operates in kernel mode on Windows systems, intercepts network traffic, and waits for specially crafted packets that contain encrypted operator instructions. This passive architecture reduces overt command-and-control activity and supports stealthy post-compromise operations.
White Lambert is associated with the broader Lambert malware ecosystem, a high-end espionage framework active since at least 2008 and linked to multiple related families including Black Lambert, Blue Lambert, Green Lambert, Pink Lambert, and Gray Lambert. Within that ecosystem, White Lambert represents the kernel-mode passive-listener component, contrasting with more active implants such as Black Lambert and serving as a precursor to Gray Lambert, a later user-mode passive implant with similar functionality. Migration from White Lambert to Gray Lambert was observed through 2016.
A notable technical characteristic of White Lambert is its abuse of a vulnerable signed third-party driver to execute unsigned code in kernel mode on 64-bit Windows, enabling deep traffic interception and defense evasion. Its role in the Lambert arsenal indicates use in targeted intrusions against high-value victims as part of long-term espionage operations. The Lambert toolkit as a whole has been assessed as exceptionally sophisticated, with tradecraft comparable to other top-tier state-linked intrusion platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
White Lambert is a fully passive, network-driven backdoor... White Lambert samples run in kernel mode and sniff network traffic looking for special packets containing instructions to execute.
White Lambert is a fully passive, network-driven backdoor... White Lambert samples run in kernel mode and sniff network traffic looking for special packets containing instructions to execute.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced Lambert-family kernel-mode passive listener implant; mentioned in relation to Gray Lambert replacement and Purple Lambert similarities.
A passive network-driven backdoor in the Lamberts toolkit. It runs in kernel mode, intercepts/sniffs network traffic, decrypts specially crafted packets for instructions, and uses a signed driver abuse technique to load unsigned code on 64-bit Windows.
A passive, network-driven backdoor/implant that runs in kernel mode and sniffs/intercepts network traffic, decrypting specially crafted packets to extract and execute instructions. Uses an exploit against a signed legitimate driver (SiSoftware Sandra) to load unsigned kernel code on 64-bit Windows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.