Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lunalock

Description

LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid. Known victims: 2 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

LunaLock, identified as a medium-sophistication criminal threat actor emerging in September 2025, primarily operates through ransomware campaigns targeting creative and digital sectors. Known for breaching an illustrator marketplace and a Mexican ISP, LunaLock utilizes threatening strategies to coerce victims into paying ransoms. Their operations are limited but demonstrate moderate technical proficiency, focusing on financial gain through extortion.

Goals & Targeting

LunaLock's primary objectives revolve around organizational and financial gains through ransomware activities. Their targeting strategy focuses on creative and digital sectors, likely due to the high value of intellectual property and the potential for severe reputational damage when stolen data is involved. By selecting specific victims within these industries, LunaLock aims to maximize leverage and minimize detection risk. The choice of sectors and countries seems calculated, potentially reflecting operational capabilities or strategic interests that are still under development.

Enhanced Description

LunaLock has emerged as a notable threat actor in the cybercriminal landscape, operating with marked precision in targeting creative and digital platforms. Since their inception in September 2025, they have successfully compromised an illustrator marketplace and a Mexican ISP, showcasing their ability to penetrate sectors where intellectual property is highly valued. Their modus operandi involves leveraging stolen data as leverage for extortion, as evidenced by threats to submit artwork samples to AI training repositories if ransoms are not met. These tactics indicate a strategic approach to maximize the psychological impact on victims while ensuring financial gain through ransomware distribution.

Key Capabilities

  • Sophisticated use of phishing techniques
  • Distribution of ransomware through malicious email payloads
  • Threatening data exposure for coercive purposes

MITRE ATT&CK Tactics

Email Delivery
Infection & Execution

ATT&CK Techniques

T1059.003

Software / Tooling

Malicious Email Payloads
(Possibly) Phishing Campaign Tools

Campaigns & Victims

LunaLock's known campaigns include at least one successful phishing attack with ransomware distribution. They have demonstrated the ability to target specific sectors, including creative industries and ISPs. Notably, their campaign involving an illustrator marketplace highlights their understanding of data leverage for extortion. Despite emerging in September 2025, LunaLock's relatively short operational timeline indicates early-stage activity that may evolve over time.

IOC Patterns

  • Spear-phishing via malicious email attachments
  • Email-based C2 communications

Recommended Actions

  • Enhance email filtering and threat detection capabilities
  • Conduct regular user training on phishing awareness
  • Monitor for异常 network traffic patterns indicative of lateral movement and ransomware deployment

Suggested Tags

ransomware
cybercrime
financial-gain
intellectual-property-theft

Confidence Assessment

Confidence in LunaLock's intelligence is moderate to low due to limited operational history and specific targeting details. The threat actor's emergence in late September 2025 suggests they may still be refining their methods. Key gaps include an unclear geographic focus, unelaborated tools, and limited campaign information beyond the known victims.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
cybercrime
financial-gain
intellectual-property-theft

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 2, 2025
Last Seen
Sep 13, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.