Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Green Lambert

Green Lambert

TLP:CLEAR
Family

AI Analysis

· 7 hours ago

Executive Summary

Green Lambert is a highly adaptable, cross‑platform backdoor linked to advanced groups Longhorn and The Lamberts. It offers modular payload deployment, persistent remote control, and data exfiltration capabilities across Windows, macOS, iOS, and Linux systems. Its early presence indicates it has been used covertly for many years.

Enhanced Description

Green Lambert is a modular backdoor that has been linked to the advanced threat groups Longhorn and The Lamberts. Although officially first reported in 2017, evidence suggests its Windows version may have been operational as early as 2008, while a macOS variant was uploaded to a multi‑scanner service in September 2014. The malware is designed for broad platform reach—running on Windows, iOS, macOS and Linux—which allows an attacker to maintain persistent footholds across an organization’s heterogeneous environment. Functionally, Green Lambert acts as a remote command-and-control (C2) agent that can receive modular payloads via the network. Its architecture enables the download of additional components, execution of arbitrary scripts, and collection of credential or sensitive data for exfiltration. The backdoor’s cross‑platform capabilities suggest shared binaries that have been adapted or recompiled for each operating system, facilitating a consistent attacker toolkit. Operationally, security researchers estimate that Green Lambert is employed in long‑term espionage missions rather than opportunistic attacks. Its presence on an endpoint can provide the adversary with persistent lateral movement opportunities and covert data exfiltration channels. The limited publicly available sample size means detailed technical behaviors have not been fully enumerated, but the pattern aligns with other modular backdoors used by sophisticated threat actors to adapt quickly to different OSes and maintain stealth over extended periods.

Key Capabilities

  • Modular architecture supporting dynamic code downloads
  • Cross‑platform (Windows, macOS, iOS, Linux) operation
  • Persistent remote command execution via C2
  • Credential harvesting and data exfiltration
  • Potential use of obfuscated or encrypted payloads

Description

Green Lambert is a modular backdoor that security researchers assess has been used by an advanced threat group referred to as Longhorn and The Lamberts. First reported in 2017, the Windows variant of Green Lambert may have been used as early as 2008; a macOS version was uploaded to a multiscanner service in September 2014.(Citation: Kaspersky Lamberts Toolkit April 2017)(Citation: Objective See Green Lambert for OSX Oct 2021)

Details

Type
Malware
Platforms
Windows
Ios
Macos
Linux
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.