Luna is a ransomware family written in Rust and described in reporting as part of the broader trend of newer ransomware families using Rust or Go to build cross-platform malware. It has been observed in the wild and has been listed among ransomware families targeting VMware ESXi environments. Reporting also shows Luna was advertised as a ransomware-as-a-service program on the Russian-language cybercrime forum RAMP, where a June 2022 listing indicated an 85/15 affiliate-operator revenue split. The available content does not provide high-confidence details on Luna’s specific infection chain, encryption routine, ransom note format, associated threat actor, or unique indicators of compromise beyond its use as ransomware, its Rust implementation, its presence in the wild, its ESXi targeting, and its appearance in RaaS advertising.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
RAMP hosted 60 threads in its dedicated RaaS section, where ransomware operators recruit affiliates... We identified 14 distinct RaaS programs: AvosLocker, Conti, Luna, BEAST, Nevada, CryptNet, Knight 3.0, NoEscape, Bl00dy, KUIPER, UBUD, PHOBOS, Zeppelin2, Wing 1.0.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service program advertised on RAMP; noted as Rust-based in the listing.
A non-Babuk-based ransomware strain targeting VMware ESXi virtual machines.
Ransomware family mentioned as adopting Rust for cross-platform malware development/distribution.
Agenda is also among the crop of ransomware families such as BlackCat, Hive, and Luna to use newer programming languages like Go and Rust.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.