Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the high profile attack from 2014 used a very complex Windows TTF zero-day exploit (CVE-2014-4148). The vulnerability was patched by Microsoft at the same time. | The attack leveraged malware we called ‘BlackLambert’... The only known sample of Black Lambert was dropped by a TTF-exploit zero day (CVE-2014-4148).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attack leveraged malware we called ‘BlackLambert’... The only known sample of Black Lambert was dropped by a TTF-exploit zero day (CVE-2014-4148).
The attack leveraged malware we called ‘BlackLambert’... The only known sample of Black Lambert was dropped by a TTF-exploit zero day (CVE-2014-4148).
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An active implant/backdoor from the Lamberts toolkit. It was deployed via the CVE-2014-4148 TTF zero-day exploit and connects directly to its C2 for instructions.
An active implant/backdoor (delivered via a Windows TTF zero-day exploit CVE-2014-4148) that connects directly to C2 for instructions; observed as a loader plus a final payload DLL and apparently tailored to specific victim network configurations (proxy in config).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.