Luna is a ransomware family first observed in mid-2022 and notable for targeting VMware ESXi from the outset while also supporting Windows and Linux. It is written in Rust, reflecting the broader shift toward cross-platform ransomware development using modern languages. Luna has been described as operating under a ransomware-as-a-service model, with reporting indicating participation was limited to Russian-speaking affiliates. Linguistic characteristics in embedded ransom-note text have also been assessed as consistent with Russian-speaking operators.
Luna is designed to encrypt files across multiple operating systems using an encryption scheme involving X25519 and AES. Linux and ESXi variants appear to share substantially the same code base as the Windows version, with only minor platform-specific changes. On Linux-family targets, execution relies on command-line arguments, and the malware can present usage information when launched without them. In ESXi environments, Luna is significant because compromise of virtualization hosts can disrupt many guest systems simultaneously and amplify operational impact.
Unlike several other ESXi-focused ransomware families, Luna has been reported not to shut down virtual machines before encrypting associated files. That behavior can increase the risk of file corruption and may complicate recovery or decryption. Available reporting consistently characterizes Luna as an encrypting extortion malware family rather than a stealth access tool or information stealer.
Luna has been discussed alongside other Rust-based ransomware families such as BlackCat and Hive as part of the evolution toward portable, multi-platform ransomware capable of hitting enterprise servers and virtualization infrastructure. Victimology details remain comparatively limited in public reporting, but the family is clearly associated with attacks against virtualized enterprise environments, especially ESXi systems where a single successful intrusion can have infrastructure-wide consequences.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service program advertised on RAMP; noted as Rust-based in the listing.
Ransomware family mentioned as another Rust-based comparator.
A non-Babuk-based ransomware strain targeting VMware ESXi virtual machines.
Rust-based RaaS ransomware that targets ESXi from inception, encrypts files with X25519 and AES, appends .Luna, and does not shut down VMs before encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.