Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions
ID: 9134152f-a43c-5b45-8149-f1d93c1ade2f
STIX ID: report--9134152f-a43c-5b45-8149-f1d93c1ade2f
Feed Name: The Hacker News
ESET attributes a targeted espionage campaign against a European Ministry of Foreign Affairs and three Middle East diplomatic missions to the Russia-aligned Turla APT, describing two previously undocumented implants: LunarWeb (server-side, HTTP(S) C2 mimicking legitimate traffic) and LunarMail (Outlook add-in using email attachments for C2); the report covers suspected spear-phishing/Zabbix misuse initial vectors, lateral movement, persistence, and exfiltration capabilities, with activity traced back to at least early 2020.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
