Research presented at LABScon described a methodology for clustering malware tied to the Lamberts threat actor, also referred to as Bright Constellation, using YARA, auxiliary scripting, and open-source reverse-engineering tools. Starting with about 50 VirusTotal samples and limited prior public reporting from Kaspersky, Symantec, and FireEye, the researcher moved beyond simple overlaps such as import hashes, PDB paths, DLL names, and section or resource hashes to more durable code-similarity techniques based on executable sections, entry points, export functions, and called functions.
The workflow combined YARA console output with tools including FLOSS, Vivisect, and Rizin, and introduced an open-source utility, Floss2YAR, to generate code-focused YARA rules from likely decoding functions. Using that process, the research linked 14 of 21 known Lambert malware families, including Rationalist, Marianas Trench, Invisible Enemy, Bloodletter, Existence, and Escape Artist, and found the tooling commonly ran as Windows services while emphasizing stealth against experienced administrators and Windows logging or telemetry rather than user-lure tactics or obvious antivirus evasion.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
At LABScon, Greg Lesnewich of Proofpoint presented personal research on using YARA, auxiliary scripting, and open-source tools to analyze and cluster malware associated with the Lamberts, also referred to as Bright Constellation. He said the workflow linked 14 of 21 Lambert malware families and included an open-sourced tool called Floss2YAR.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.