To the Moon and back(doors): Lunar landing in diplomatic missions
ID: 754a750e-6054-5fb7-9588-5784f500f12f
STIX ID: report--754a750e-6054-5fb7-9588-5784f500f12f
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers uncovered two novel backdoors, LunarWeb (server-side, HTTP(S) C2 with protocol impersonation and steganography) and LunarMail (Outlook add-in, email-based C2 with PNG/PDF steganographic exfiltration), used since at least 2020 to compromise a European ministry of foreign affairs and its diplomatic missions; the toolset uses environmental keying, reflective loading, RSA-4096/AES-256 encryption, supports Lua scripting, multiple persistence techniques, and includes extensive IoCs and MITRE ATT&CK mappings, with attribution to the Turla APT at medium confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
