Longhorn__2020__Longhorn_Tools_used_by_cyberespionage_group_linked_to_Vault_7.pdf
ID: 3e0adacc-9a76-4449-b7f9-bff1ed92d420
STIX ID: report--3e0adacc-9a76-4449-b7f9-bff1ed92d420
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2020-03-04
Last Modified Date: 2020-03-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details the activity of Longhorn, an advanced espionage group linked to Vault 7, describing its use of multiple custom backdoors (Corentry, Plexor, LH1, LH2), zero-day exploits, and Vault 7-derived tradecraft (custom crypto, in-memory obfuscation, RTP C2 techniques). The report correlates malware samples and compilation metadata to Vault 7 changelogs, catalogs target-specific indicators (codewords, domains, sample hashes), and characterizes Longhorn as a well-resourced, likely state-affiliated operator conducting targeted intelligence-gathering across governments and critical sectors.
