ESET disclosed DePriMon, a multi-stage malicious downloader and malware framework active since at least 2017, after finding it at a private company in Central Europe and on dozens of systems in the Middle East. Its most distinctive persistence technique abuses the Windows print subsystem by registering a malicious DLL as a local port monitor named "Windows Default Print Monitor", causing spoolsv.exe to load it with SYSTEM privileges at startup. Researchers said the malware uses reflective DLL loading, extensive AES-256 encryption, a large encrypted configuration, and TLS communications implemented through SSPI and Schannel, while its initial infection vector and final payloads remain unknown.
The findings add to evidence tying DePriMon to the Lamberts cyberespionage platform, also known as Longhorn, a highly sophisticated toolkit previously documented by Kaspersky and linked by Symantec to the actor exposed in Vault 7 reporting. Kaspersky described the Lamberts as an elite espionage framework active since at least 2008, with multiple color-coded malware families including Black, White, Blue, Green, Pink, and Gray Lambert, plus capabilities such as modular backdoors, packet-sniffing implants, in-memory plugin execution, signed-driver abuse, and use of the CVE-2014-4148 TrueType Font zero-day against a European target. ESET noted some DePriMon infections appeared alongside ColoredLambert, reinforcing the assessment that the downloader is connected to the broader Longhorn/Lamberts arsenal.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
On November 21, 2019, ESET published technical analysis of DePriMon, describing its multi-stage architecture, encrypted configuration handling, reflective DLL loading, and print-monitor persistence technique. The researchers said the initial infection vector and final payloads remained unknown.
On April 11, 2017, Kaspersky published its analysis of the Lamberts/Longhorn toolkit, detailing multiple related malware families and their links. The report described the actor as a top-tier cyberespionage operation.
ESET said telemetry showed the DePriMon downloader and malware framework had been active since at least March 2017. The malware used a malicious Windows print monitor for persistence and SYSTEM-level execution.
Kaspersky reported that Gray Lambert migration or upgrade activity from White Lambert infections was last observed in October 2016. The observation tied Gray Lambert to the evolution of the passive network toolset.
Kaspersky said known Lambert variants for Windows and OS X included samples created as late as 2016. This marked the latest sample creation timeframe cited in the report.
FireEye publicly reported in October 2014 that CVE-2014-4148 had been exploited as a zero-day in the wild. Microsoft patched the vulnerability when it was publicly disclosed.
Kaspersky reported that an OS X variant of Green Lambert, version 1.2.0, was uploaded to a multiscanner service in September 2014. This showed the Lamberts toolkit had cross-platform capability.
In 2014, attackers used the Windows TrueType Font zero-day CVE-2014-4148 to deliver Black Lambert against a high-profile European target. Kaspersky linked the malware to the Lamberts/Longhorn toolkit.
Kaspersky reported that the Lamberts/Longhorn cyberespionage toolkit had been in use since at least 2008. The arsenal included multiple malware families for espionage, harvesting, and wiping across Windows and OS X.
ESET reported detecting DePriMon in a private company in Central Europe and on dozens of computers in the Middle East. Some infections were observed within a short timeframe of ColoredLambert activity, suggesting possible overlap with the Lamberts/Longhorn ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
symantec.com
Open sourcewelivesecurity.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.