logo

Longhorn__2020__Unraveling_the_Lamberts_Toolkit.pdf

ID: 30dd45e8-744f-410f-89f5-839d6055e1ca

STIX ID: report--30dd45e8-744f-410f-89f5-839d6055e1ca

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2020-03-04

Last Modified Date: 2020-03-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab analyzes the Lamberts (aka Longhorn) APT toolkit — a multi-year, highly sophisticated cyber-espionage framework comprising multiple families (Black, White, Blue, Green, Pink, Gray) that use kernel- and user-mode implants, driver exploitation to load unsigned code, in-memory plugins, USB data-stealers, and a TTF zero-day (CVE-2014-4148). The report maps code/data sharing, timelines (2008–2016), internal codenames, sample metadata (hashes, filenames, PDB paths), and mitigation/detection guidance, concluding the toolkit rivals Regin/Equation/ProjectSauron in complexity.