LunarWeb
S1141 · Windows
LunarWeb is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs (MFA) together with LunarLoader and LunarMail. LunarWeb has only been observed deployed against servers and can use Steganography to obfuscate command and control.
ATT&CK S1141
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0