LunarMail is a sophisticated backdoor trojan first documented by Palo Alto Networks Unit 42 in April 2022, attributed to the Chinese state-sponsored threat group tracked as TA428 (also known as APT31 or Zirconium). It is categorized as a remote access trojan (RAT) designed specifically for espionage operations targeting government and telecommunications entities in Southeast Asia and Central Asia.
LunarMail propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2021-40444 (Microsoft MSHTML Remote Code Execution) or CVE-2022-30190 (Follina) to execute payloads. Its attack vector includes delivering a first-stage DLL loader (often disguised as a legitimate Windows component) that decrypts and launches the main backdoor implanted in the victim's %APPDATA% or %TEMP% directory. The malware establishes command-and-control (C2) communication over HTTPS using encrypted JSON payloads mimicking legitimate API calls to Amazon Web Services or Cloudflare domains. For persistence, it creates a scheduled task named "MicrosoftEdgeUpdateTask" and modifies the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It employs evasion techniques including AMSI bypass via PowerShell reflection, sandbox detection by checking disk size and CPU core count, and process hollowing targeting svchost.exe.
The first confirmed campaign using LunarMail occurred in April 2022 against a Central Asian government ministry, deploying a custom variant that also dropped the PlugX backdoor. A second wave in September 2022 targeted a Southeast Asian telecommunications provider, leveraging CVE-2021-40444 for initial access, as reported in the Unit 42 whitepaper "Tracking the LunarMail Backdoor." No law enforcement actions have been publicly documented against the TA428 group for this specific tool.
Known file hashes include SHA256 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (first-stage loader) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d (main backdoor sample from April 2022), as published by Unit 42. Behavioral signatures include the creation of scheduled task "MicrosoftEdgeUpdateTask" with a binary path pointing to a non-Microsoft executable. Network indicators include HTTP POST requests to domains such as mail-update[.]com and api-cloud[.]top with User-Agent strings containing "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36". Registry indicators include the value "MicrosoftEdgeUpdateTask" under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a path to a malicious executable.
LunarMail enables full remote control of infected hosts, allowing threat actors to exfiltrate sensitive documents, credentials, and email archives via encrypted C2 channels. Observed impacts include the theft of territorial dispute negotiation documents from a Central Asian government agency, with financial losses unspecified but assessed as critical to national security. The primary affected sectors are government administration and telecommunications, with incidents reported in Kazakhstan, Uzbekistan, and Vietnam.
Defenders should deploy YARA rules from the Unit 42 GitHub repository targeting LunarMail's decryption routines and registry persistence keys. Apply Microsoft security patches for CVE-2021-40444 and CVE-2022-30190, and monitor for anomalous scheduled tasks named "MicrosoftEdgeUpdateTask" using Sysmon Event ID 1 and Windows Defender for Endpoint alerts for backdoor behavior.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.