PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Symantec Links Trojans, Malware to CIA Hacking Tools

A series of computer viruses targeting companies and organizations closely resembles the Vault 7 hacking tools that WikiLeaks disclosed.

 & Tom Brant Managing Editor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

CIA hacking tools that WikiLeaks exposed as part of its Vault 7 data dump are linked to a rash of trojans and zero-day vulnerabilities that have infected computers since 2011, anti-virus software Symantec claimed this week.

The attacks, which Symantec researchers have lumped together into a single virus that they codenamed "Longhorn," have targeted at least 40 different organizations in 16 countries in the Middle East, Europe, Asia, and Africa. The victims include companies in the financial, telecom, energy, aerospace, IT, education, and natural resources sectors, as well as governments and international NGOs.

Symantec made the link between Longhorn and the WikiLeaks CIA hacking trove using changelog data, which shows that new features were added to the CIA tools at the same time as updates to some of Longhorn's tools. Other similarities exist, too, including cryptographic practices and the methods that both sets of tools use to cover their tracks on the systems they infect.

"Longhorn has used advanced malware tools and zero-day vulnerabilities to infiltrate a string of targets worldwide," Symantec said in a blog post. "Taken in combination, the tools, techniques, and procedures employed by Longhorn are distinctive and unique to this group, leaving little doubt about its link to Vault 7."

Symantec said it first became aware of Longhorn in 2014, and that its anti-virus products provide protection against the malware. The company hasn't identified any domestic targets; although it observed one computer in the US infected with Longhorn, the virus uninstalled itself within hours, suggesting that the infection was inadvertent.

WikiLeaks first announced its possession of the Vault 7 hacking tools in early March, claiming that they were widely circulated among government contractors, one of whom leaked them to the organization.

About Our Expert

Tom Brant

Tom Brant

Managing Editor

I’m a managing editor at PCMag.com focused on PC hardware. Reading this during the day? Then you've caught me testing gear and editing reviews of Wi-Fi routers, printers, laptops, and tons of other personal tech. (Reading this at night? Then I’m probably dreaming about all those cool products.) I’ve covered the consumer tech world as an editor, reporter, and analyst since 2015.

I've covered most major consumer tech events, including CES, Computex, Google I/O, and IFA. I've also appeared on CBS News, in USA Today, and at many other outlets to offer analysis on breaking technology news.

Before I joined the tech-journalism ranks, I wrote on topics as diverse as Borneo's rainforests, Middle Eastern airlines, and Big Data's role in presidential elections. A graduate of Middlebury College, I also have a master's degree in journalism and French Studies from New York University.

The Technology I Use

While most people buy a phone or laptop and stick with it for years, I’m lucky enough to use devices based on Android, iOS, macOS, and Windows daily as part of my job. As a result, I cycle through lots of tech in addition to my IT-issue work laptop. (Yes, that's a ThinkPad.) Personally, I’ve also owned a lot of tech products both cutting-edge and cringeworthy, from the Nintendo GameCube and the original MacBook to the Palm m105 and the CueCat.

Read full bio