Skip to content

Luna

Luna is a Rust-based ransomware family first identified in July 2022.

Profile source: Mallory opens in a new tab

Luna

Family profile

Luna is a Rust-based ransomware family first identified in July 2022. It has Windows, Linux, and VMware ESXi variants and has been associated with a ransomware-as-a-service operation. Luna encrypts victim data using AES in CTR mode with per-file X25519 key material, appends a ransomware-specific marker and public key material to encrypted files, and renames affected files with its characteristic extension. The Windows variant enumerates drives and attempts to disable or stop numerous services and terminate processes, including security, backup, database, and business-application software, before encrypting files. Linux variants support file- and directory-targeted encryption but may encrypt critical system files, potentially destabilizing the affected host. Luna has targeted ESXi environments from its early operations; its ESXi encryptor does not reliably shut down virtual machines before encryption, creating risks of virtual-disk corruption. Ransom notes threaten extortion, although confirmed data-exfiltration functionality is not established for the analyzed samples.

Capabilities

  • Defense Evasion
  • Extortion
  • Reconnaissance

MITRE ATT&CK

Luna in ATT&CK

1 distinct techniques

Reporting

Research mentioning Luna

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.