LunarMail
MITRE ATT&CK: S1142 View on attack.mitre.org
Aliases: LunarMail
- First seen
- 2020-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:10:30
Targeted industries: government-and-public-sector
Targeted regions: country_code:eu
Context
LunarMail is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs (MFA) in conjunction with LunarLoader and LunarWeb. LunarMail is designed to be deployed on workstations and can use email messages and Steganography in command and control.
Detection coverage
- 162 Sigma rules
Malware & tools used
- Local Email Collection (attack-pattern)
- Clear Mailbox Data (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- File Deletion (attack-pattern)
- System Information Discovery (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Steganography (attack-pattern)
- Screen Capture (attack-pattern)
- Create or Modify System Process (attack-pattern)
- Mail Protocols (attack-pattern)
- Add-ins (attack-pattern)
- Local Data Staging (attack-pattern)
Used by threat actors
- Turla (threat-actor)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Lunarmail (report)
- ESET — Moon Backdoors Lunar Landing Diplomatic Missions (report)
- MITRE ATT&CK — S1142 (report)