logo

To the Moon and back(doors): Lunar landing in diplomatic missions

ID: 754a750e-6054-5fb7-9588-5784f500f12f

STIX ID: report--754a750e-6054-5fb7-9588-5784f500f12f

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-05-15

Date Updated: 2026-05-01

...
...

ESET researchers uncovered two novel backdoors, LunarWeb (server-side, HTTP(S) C2 with protocol impersonation and steganography) and LunarMail (Outlook add-in, email-based C2 with PNG/PDF steganographic exfiltration), used since at least 2020 to compromise a European ministry of foreign affairs and its diplomatic missions; the toolset uses environmental keying, reflective loading, RSA-4096/AES-256 encryption, supports Lua scripting, multiple persistence techniques, and includes extensive IoCs and MITRE ATT&CK mappings, with attribution to the Turla APT at medium confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.