Malware.View on attack.mitre.org
LunarWeb is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs (MFA) together with LunarLoader and LunarMail. LunarWeb has only been observed deployed against servers and can use Steganography to obfuscate command and control.
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images. |
| T1016 System Network Configuration Discovery |
LunarWeb can use shell commands to discover network adapters and configuration. |
| T1027.013 Encrypted/Encoded File |
The LunarWeb install files have been encrypted with AES-256. |
| T1030 Data Transfer Size Limits |
LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB. |
| T1033 System Owner/User Discovery |
LunarWeb can collect user information from the targeted host. |
| T1047 Windows Management Instrumentation |
LunarWeb can use WMI queries for discovery on the victim host. |
| T1049 System Network Connections Discovery |
LunarWeb can enumerate system network connections. |
| T1057 Process Discovery |
LunarWeb has used shell commands to list running processes. |
| T1059.001 PowerShell |
LunarWeb has the ability to run shell commands via PowerShell. |
| T1059.003 Windows Command Shell |
LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output. |
| T1069.001 Local Groups |
LunarWeb can discover local group memberships. |
| T1070.004 File Deletion |
LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail. |
| T1071.001 Web Protocols |
LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands. |
| T1082 System Information Discovery |
LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system. |
| T1083 File and Directory Discovery |
LunarWeb has the ability to retrieve directory listings. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.