logo

Longhorn: Tools used by cyberespionage group linked to Vault 7

ID: 36d77251-0fc5-4fdf-b521-8e3ca3ae9b35

STIX ID: report--36d77251-0fc5-4fdf-b521-8e3ca3ae9b35

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2018-08-10

Last Modified Date: 2018-08-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec links the Longhorn espionage group to Vault 7 leaked tooling, describing multiple custom backdoors (Corentry, Plexor, LH1/LH2), use of zero-day exploits, bespoke C2 and cryptographic protocols, and targeted operations against ~40 organizations across 16 countries; the report describes distinctive tradecraft, compilation/timeline correlations with Vault 7 documents, and protections/detections provided by Symantec.