logo

Longhorn__2020__Longhorn_Tools_used_by_cyberespionage_group_linked_to_Vault_7.pdf

ID: 3e0adacc-9a76-4449-b7f9-bff1ed92d420

STIX ID: report--3e0adacc-9a76-4449-b7f9-bff1ed92d420

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2020-03-04

Last Modified Date: 2020-03-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec details the activity of Longhorn, an advanced espionage group linked to Vault 7, describing its use of multiple custom backdoors (Corentry, Plexor, LH1, LH2), zero-day exploits, and Vault 7-derived tradecraft (custom crypto, in-memory obfuscation, RTP C2 techniques). The report correlates malware samples and compilation metadata to Vault 7 changelogs, catalogs target-specific indicators (codewords, domains, sample hashes), and characterizes Longhorn as a well-resourced, likely state-affiliated operator conducting targeted intelligence-gathering across governments and critical sectors.