Luna is a Rust-based ransomware family first identified in July 2022. It has Windows, Linux, and VMware ESXi variants and has been associated with a ransomware-as-a-service operation. Luna encrypts victim data using AES in CTR mode with per-file X25519 key material, appends a ransomware-specific marker and public key material to encrypted files, and renames affected files with its characteristic extension. The Windows variant enumerates drives and attempts to disable or stop numerous services and terminate processes, including security, backup, database, and business-application software, before encrypting files. Linux variants support file- and directory-targeted encryption but may encrypt critical system files, potentially destabilizing the affected host. Luna has targeted ESXi environments from its early operations; its ESXi encryptor does not reliably shut down virtual machines before encryption, creating risks of virtual-disk corruption. Ransom notes threaten extortion, although confirmed data-exfiltration functionality is not established for the analyzed samples.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service program advertised on RAMP; noted as Rust-based in the listing.
Ransomware family mentioned as another Rust-based comparator.
A non-Babuk-based ransomware strain targeting VMware ESXi virtual machines.
Rust-based RaaS ransomware that targets ESXi from inception, encrypts files with X25519 and AES, appends .Luna, and does not shut down VMs before encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.