Longhorn: Tools used by cyberespionage group linked to Vault 7
ID: 36d77251-0fc5-4fdf-b521-8e3ca3ae9b35
STIX ID: report--36d77251-0fc5-4fdf-b521-8e3ca3ae9b35
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2018-08-10
Last Modified Date: 2018-08-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec links the Longhorn espionage group to Vault 7 leaked tooling, describing multiple custom backdoors (Corentry, Plexor, LH1/LH2), use of zero-day exploits, bespoke C2 and cryptographic protocols, and targeted operations against ~40 organizations across 16 countries; the report describes distinctive tradecraft, compilation/timeline correlations with Vault 7 documents, and protections/detections provided by Symantec.
