VORANT. Threat Intelligence Sign in Get the full feed

Researcher dissects CIA's OSX.GreenLambert implant

medium threat financial-servicestelecommunicationsenergyeducationgovernment-national

A deep-dive technical analysis reverse-engineers the CIA-linked Green Lambert (GrowlHelper) macOS implant tied to the Vault 7 leak and The Lamberts/Longhorn actor.

This Objective-See blog post presents a detailed static and dynamic analysis of OSX.GreenLambert (also known as GrowlHelper), a macOS implant attributed to the threat actor tracked by Symantec as Longhorn and by Kaspersky as The Lamberts. The implant is linked to the CIA's hacking toolkit exposed in the 2017 Vault 7 WikiLeaks disclosure. The analysis covers persistence mechanisms (LaunchAgents, LoginItems, shell profile hijacking), encrypted string handling, command-line argument discovery, and network communication with a hardcoded C2 domain and IP address, revealing tradecraft consistent with CIA development guidelines also leaked via Vault 7.

The researcher determined the implant is a 32-bit Mach-O executable targeting OS X 10.7 (Lion) and later, likely developed and used between 2007 and 2013 based on library versions and API usage. It communicates with a "Listening Post" (the actor's term for C2 infrastructure) via login.php, getconf.php, and getfile.php, using the hardcoded domain notify.growlupdate[.]com and IP 94.242.252[.]68, which Kaspersky later sinkholed. Analysis of encrypted strings, entry-point structure, and adherence to CIA development tradecraft guidelines (file size, C2 jitter, secure erase, encrypted logs) provides insight into the sophistication and terminology used by this long-running threat actor.

Historically, Symantec reported that Longhorn/The Lamberts has targeted governments and organizations in financial, telecom, energy, aerospace, IT, education, and natural resources sectors, while QI-ANXIN noted targeting of personnel and institutions in China. The actor's toolkit reportedly includes network-driven backdoors, modular backdoors, harvesting tools, and wipers, with Green Lambert described as the oldest and longest-running implant in the family, and newer variants (e.g., Purple Lambert) continuing to surface as recently as 2021.

Mentioned in this report

Threat actors The Lamberts
Malware KazuarOSX.GreenLambertPurple Lambert
Campaigns Vault 7

Source reporting: https://objective-see.org/blog/blog_0x68.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free