logo

Russian hackers use new Lunar malware to breach a European govt's agencies

ID: 7f8a0fdd-f2e2-5605-8d99-8653fccb1f3a

STIX ID: report--7f8a0fdd-f2e2-5605-8d99-8653fccb1f3a

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ESET researchers uncovered a long-running, targeted intrusion campaign using two backdoors—LunarWeb (server-focused) and LunarMail (Outlook-focused)—to surveil and exfiltrate data from a European Ministry of Foreign Affairs and its diplomatic missions; the malware uses steganography, a custom LunarLoader (RC4/AES-256), multiple persistence techniques, and likely leveraged domain controller access for rapid lateral movement, with IoCs provided and medium-confidence attribution to the Russian APT Turla.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.