Green Lambert
MITRE ATT&CK: S0690 View on attack.mitre.org
Aliases: Green Lambert
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows, ios, macos, linux
- Profile updated
- 2026-07-07 14:37:17
Targeted industries: government-and-public-sector energy-and-utilities healthcare-and-pharmaceutical
Context
Green Lambert is a modular backdoor that security researchers assess has been used by an advanced threat group referred to as Longhorn and The Lamberts. First reported in 2017, the Windows variant of Green Lambert may have been used as early as 2008; a macOS version was uploaded to a multiscanner service in September 2014.
Detection coverage
- 237 Sigma rules
Malware & tools used
- Launch Daemon (attack-pattern)
- Keychain (attack-pattern)
- System Information Discovery (attack-pattern)
- DNS (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Proxy (attack-pattern)
- Login Items (attack-pattern)
- File Deletion (attack-pattern)
- Data from Local System (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Unix Shell (attack-pattern)
- Unix Shell Configuration Modification (attack-pattern)
- Launch Agent (attack-pattern)
- RC Scripts (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Time Discovery (attack-pattern)
Reports & references
- objective-see.com — Blog 0X68 (report)
- MITRE ATT&CK — S0690 (report)
- Kaspersky — 77990 (report)