Luna Tempest is a financially motivated extortion threat actor tracked by Microsoft, previously designated Storm-0744. The group is assessed as a relatively small operator set primarily based in the United States and the United Kingdom. It is associated with aggressive, personalized coercion rather than conventional ransomware deployment and is characterized as an extortion-only actor. Luna Tempest has focused on startups and emerging companies, with repeated targeting of insurance, financial technology, biotechnology, and pharmaceutical organizations. Its operations emphasize pressure on victim leadership and corporate decision-makers. Reported behavior includes direct harassment of executives, use of encrypted communications platforms for victim contact, cryptocurrency-based payment demands, and in some cases pressure tactics extending to executives’ family members. The group has also been linked to SIM-swapping activity used to intensify extortion pressure and, in at least one case, to direct notification of a securities regulator about a breach in order to increase leverage over a victim. The actor is notable for pursuing data-theft and coercive extortion workflows without typically deploying ransomware encryption. Its tradecraft therefore aligns more closely with theft-driven post-compromise extortion and victim intimidation than with disruptive locker operations. Luna Tempest has been discussed alongside other financially motivated actors such as Octo Tempest and LAPSUS$, but it is distinct in its extortion-centric operating model and focus on emerging companies in selected sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Extortion-only actor (no ransomware encryption observed in this discussion) that targets startups and emerging companies, with aggressive harassment tactics (e.g., direct pressure on executives, SIM swapping, and in some cases targeting family members) to coerce payment, and uses Tox for victim communications.
Mentioned as a Microsoft-tracked threat actor name used for adversary emulation/TTP-chain questions; no specific activity details provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.