Luna is a ransomware-as-a-service operation that emerged in 2022 and is notable for targeting VMware ESXi environments from the outset. The ransomware is written in Rust and includes Linux-focused capabilities aimed at virtualized infrastructure, reflecting an emphasis on high-impact enterprise disruption through encryption of virtualization hosts. Luna has been observed using asymmetric and symmetric cryptography based on X25519 and AES. It is associated with an affiliate revenue split model consistent with RaaS operations. Luna is part of the broader wave of ransomware families that expanded to Linux and ESXi targets as attackers increasingly pursued hypervisors and shared virtual infrastructure to maximize operational impact. Its ESXi-focused behavior has been noted as unusual for a newly emerged ransomware family because it incorporated support for VMware environments from the beginning rather than adding it later. Luna reportedly does not shut down virtual machines before encryption, a behavior that can increase the risk of file corruption and failed recovery. Known aliases include Luna Ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS program advertised on RAMP offering an 85/15 affiliate/operator split; noted as Rust-based in the table.
Named ransomware operation cited as one of several non-Babuk-based strains targeting VMware ESXi virtual machines.
RaaS ransomware written in Rust that targeted VMware ESXi from inception and encrypts files without shutting down VMs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.