LUNA Ransomware Attack Pattern Analysis
ID: 1ee06687-3bcc-5293-af8e-6c853f506735
STIX ID: report--1ee06687-3bcc-5293-af8e-6c853f506735
Feed Name: Elastic Security Labs
This report analyzes LUNA (REF5264), a Rust-based ransomware family with cross-platform Windows and Linux samples. It documents execution arguments (-file, -dir), differences between a more mature Windows variant and a less-polished Linux variant, service/process termination and drive enumeration techniques, a per-file X25519 key-exchange → AES-CTR encryption scheme with a hardcoded IV and embedded public keys, the ransom note behavior, and detection guidance including a YARA rule and an endpoint prevention rule targeting pre-encryption defense-evasion TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
