ATT&CKSoftwareLunarLoader

LunarLoader

S1143

Malware.View on attack.mitre.org

About this malware

LunarLoader is the loader component for the LunarWeb and LunarMail backdoors that has been used by Turla since at least 2020 including against a European ministry of foreign affairs (MFA). LunarLoader has been observed as a standalone and as a part of trojanized open-source software such as AdmPwd.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1016
System Network Configuration Discovery

LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key.

T1137.006
Add-ins

LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence.

T1140
Deobfuscate/Decode Files or Information

LunarLoader can deobfuscate files containing the next stages in the infection chain.

T1480
Execution Guardrails

LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets.

T1620
Reflective Code Loading

LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Turla Lunar toolset May 2024 Open source
    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.