Luna
Luna is a Rust-based ransomware family first identified in July 2022.
Profile source: Mallory opens in a new tabLuna
Family profile
Luna is a Rust-based ransomware family first identified in July 2022. It has Windows, Linux, and VMware ESXi variants and has been associated with a ransomware-as-a-service operation. Luna encrypts victim data using AES in CTR mode with per-file X25519 key material, appends a ransomware-specific marker and public key material to encrypted files, and renames affected files with its characteristic extension. The Windows variant enumerates drives and attempts to disable or stop numerous services and terminate processes, including security, backup, database, and business-application software, before encrypting files. Linux variants support file- and directory-targeted encryption but may encrypt critical system files, potentially destabilizing the affected host. Luna has targeted ESXi environments from its early operations; its ESXi encryptor does not reliably shut down virtual machines before encryption, creating risks of virtual-disk corruption. Ransom notes threaten extortion, although confirmed data-exfiltration functionality is not established for the analyzed samples.
Capabilities
- Defense Evasion
- Extortion
- Reconnaissance
MITRE ATT&CK
Luna in ATT&CK
1 distinct techniquesReporting