LunarMail — Malware Profile

LunarMail is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs (MFA) in conjunction with LunarLoader and LunarWeb. LunarMail is designed to be deployed on workstations and can use email messages and Steganography in command and control.

MITRE ATT&CK techniques (17)

Attributed threat actors

Read the full analysis on IntelFusions