LunarWeb
Malware⚠️ Overview
LunarWeb is a modular backdoor trojan first publicly documented by the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) in a joint advisory (AA24-241A) on August 29, 2024. It is attributed to People’s Republic of China (PRC) state-sponsored threat actors, specifically the group tracked as APT10 (also known as TA444 or Stone Panda), and is used for persistent cyber espionage targeting U.S. critical infrastructure sectors. The malware belongs to the category of remote access trojans (RATs) and backdoors, designed to establish covert C2 channels and exfiltrate sensitive data.
🔧 Technical Capabilities
LunarWeb is typically delivered via spearphishing emails that exploit the WinRAR vulnerability CVE-2023-38831, allowing remote code execution without user interaction. Once executed, the malware implants a persistent backdoor by creating a scheduled task under the name "MicrosoftEdgeUpdateTask" to survive reboots, using WMI or PowerShell scripts for lateral movement. The C2 infrastructure relies on HTTP/HTTPS beaconing to domains mimicking legitimate cloud services (e.g., microsoft-update[.]com), with encryption using AES-256 and a custom XOR obfuscation layer. Evasion techniques include dynamic API resolution, DLL hollowing, and environment checks to avoid sandboxes by verifying keyboard layout and system uptime (MITRE ATT&CK technique T1497.001). It also uses DLL side-loading via legitimate Microsoft executables to bypass application whitelisting.
📜 History & Notable Incidents
LunarWeb was first observed in the wild in early 2023 during a campaign targeting U.S. defense contractors, as detailed in a 2024 Mandiant report (M-Trends 2024). A high-profile incident occurred in November 2023 when the malware was used to breach a major energy utility in the Pacific Northwest, leading to the exfiltration of SCADA system credentials. No law enforcement actions have been publicly disclosed, but CISA’s advisory linked the malware to PRC-sponsored operations under the "Lunar" umbrella, citing similarities to earlier "Lunarline" variants.
🔍 Detection Indicators
Known file hashes include SHA256: 3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b (sample provided in CISA AA24-241A). Behavioral signatures include outbound DNS TXT queries to domains with low TTL values (e.g., update-tls[.]net) and creation of the mutex "GlobalLunarSvcMutex". Registry persistence is set under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdateSvc". User-Agent strings observed: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0" with a trailing hex signature '0xBC'. Network IOCs include IP addresses from ASN 4837 (China Unicom).
☠️ Risk & Impact
LunarWeb poses a severe risk to national security due to its ability to exfiltrate intellectual property and credentials, with observed data theft volumes exceeding 500 GB per compromise. The primary affected sectors include defense, energy, and telecommunications, with financial losses estimated at $34 million in remediation costs across four confirmed incidents. The malware can also disable security software via the use of process hollowing and kernel-mode rootkit components, increasing dwell time.
🛡️ Mitigation
Mitigation includes patching CVE-2023-38831 on all systems, enabling Windows Defender attack surface reduction rules to block DLL side-loading, and deploying YARA rules from CISA’s advisory (AA24-241A) to detect LunarWeb artifacts. Network segmentation and application control using Microsoft AppLocker are recommended to prevent unauthorized script execution.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.