Symantec announced that it has managed to connect at least 40 attacks in 16 countries, carried out with tools first announced by WikiLeaks through Vault 7, which reveals CIA espionage tactics.
In a lengthy report, Symantec talks about a highly organized group called Longhorn that the security firm says carried out these attacks. The company emphasizes that Longhorn is made up of CIA agents, and presents ample evidence.
“The tools used by Longhorn follow exactly the development timeline and technical specifications set out in the documents published by Wikileaks. The Longhorn team shares the same encryption protocols set out in the Vault 7 documents, in addition to following the same tactical guidelines to avoid detection. Given the similarities between the tools and techniques, there can be no doubt that the Longhorn activities and the documents leaked via Vault 7 are the work of the same team,” the security firm says.
Who are they at Longhorn?
Longhorn is a group that has been active since at least 2011, using a range of backdoors, trojans and zero-day vulnerabilities to gain access to its targets. The group has managed to infiltrate government organizations and companies with international operations. Its targets are companies and government organizations involved in the financial, telecommunications, energy, aerospace, information technology, education, natural resources sectors, Symantec says, but does not name them specifically.
These targets were in 16 countries across the Middle East, Europe, Asia and Africa. In one instance, a computer in the United States was compromised, but the malware was uninstalled within hours, indicating that the infection was likely unintentional.
Shortly after WikiLeaks began publishing CIA files, Symantec discovered that some of the documents contained information closely related to the development of a Longhorn tool called the Corentry trojan. Symantec announced that the tool has new features that it discovered when it was able to collect more samples.
Symantec says it has been detecting Longhorn since 2014 when it caught their attention using a zero-day exploit embedded in a Word document. Other malware used by Longhorn include Corentry, Backdoor.Trojan.LH1, and Backdoor.Trojan.LH2.
Before the WikiLeaks revelations, Symantec believed that the Longhorn group was a well-funded group engaged in intelligence gathering operations. Timestamps for the group's work showed that the hackers worked Monday through Friday, which made it pretty clear that the group was from a government agency.
