Luna Ransomware Discovered With Ability To Infect Multiple Platforms

Risk:
high
Damage:
high
Platform(s):
Microsoft® Windows OS Linux OS VMWare Esxi
Advisory ID:
ngCERT-2022-0087
Version:
N/A
CVE:
N/A
Published:
July 28, 2022

Summary


Luna, a rust-based ransomware, has been discovered that can run on Windows, Linux, and ESXi operating systems. This exemplifies the ongoing trend of threat actors developing cross-platform ransomware in order to achieve the broadest possible reach.

Description & Consequence


Luna is written in the rust programming language, which allows for easy cross-platform interoperability and the ability to avoid static analysis; in fact, the Linux and ESXi variants are compiled using the same source code, while the Windows variant differs only slightly. It also encrypts devices using a combination of Advanced Encryption Scheme (AES) and Curve25519 (Diffie-Hellman key exchange in X25519), which is quite unusual.

Because it was only recently discovered, the mode of delivery and target base have yet to be determined.

Luna encrypts data and denies access to the victim until a ransom is paid. It has also been reported that it steals data from victims' networks before encrypting their systems in order to support their double-extortion attacks.

Solution


  1. Set up a firewall
  2. Have a backup strategy that adheres to industry best practices
  3. Segment your network to prevent lateral movement of malware
  4. Build staff capacity and awareness
  5. Provide adequate endpoint security
  6. Enforce password complexity policy

Reference


Revision


Related Articles