The security firm Symantec believes it has observed one of the hacking tools described in CIA files released by WikiLeaks to a series of different attacks dating back to 2011. 

WikiLeaks’s latest series of leaks, dubbed “Vault 7,” allegedly comes from a secure CIA server. The documents focus on descriptions of CIA hacking tools, including one called Fluxwire that Symantec believes matches malware the firm had been calling Corentry. Symantec attributed Corentry to an espionage group it had been calling Longhorn.

Symantec released a writeup connecting the attacks to the CIA documents on Monday morning.

