Longhorn is a US-linked nation-state threat actor known for custom backdoors and using zero-day vulnerabilities.
Analyst brief
Longhorn (also tracked as Lamberts or APT-C-39) is a US-linked nation-state threat actor active since at least 2011. It primarily targets sectors like government, telecoms, aerospace, energy, finance, education, and media across the Middle East, Europe, Asia, and Africa. Its key TTPs involve custom backdoor Trojans and the utilization of zero-day vulnerabilities for initial access. Defenders should focus on threat hunting for unknown backdoor behavior, DLL side-loading techniques, and anomalous encrypted C2 channels.
Longhorn
Lambertsthe LambertsAPT-C-39
nation-state
Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longhorn has infiltrated governments and internationally operating organizations, in addition to targets in the financial, telecoms, energy, aerospace, information technology, education, and natural resources sectors. All of the organizations targeted would be of interest to a nation-state attacker. Longhorn has infected 40 targets in at least 16 countries across the Middle East, Europe, Asia, and Africa. On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally. According to cfr, this threat actor compromises governments, international organizations, academic institutions, and financial, telecommunications, energy, aerospace, information technology, and natural resource industries for espionage purposes. Some of the tools used by this threat actor were released by Wikileaks under the name "Vault 7."
origin (suspected)
🇺🇸USA· state-sponsoredattribution confidence: medium (50)
What technical tactics is the Longhorn (Lamberts) group known for?+
Longhorn primarily uses custom backdoor Trojans and zero-day vulnerabilities. Defenders should pay special attention to signs like DLL injection (DLL side-loading) and anomalous encrypted C2 traffic.
What sectors does the Longhorn APT group typically target?+
Longhorn targets sectors such as government, telecommunications, aerospace, energy, finance, education, media, information technology, and natural resources.