LunarMail
S1142 · Windows
LunarMail is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs (MFA) in conjunction with LunarLoader and LunarWeb. LunarMail is designed to be deployed on workstations and can use email messages and Steganography in command and control.
ATT&CK S1142
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0