LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid. Known victims: 2 1 ransom note(s) on file
Objectives
Executive Summary
LunaLock, identified as a medium-sophistication criminal threat actor emerging in September 2025, primarily operates through ransomware campaigns targeting creative and digital sectors. Known for breaching an illustrator marketplace and a Mexican ISP, LunaLock utilizes threatening strategies to coerce victims into paying ransoms. Their operations are limited but demonstrate moderate technical proficiency, focusing on financial gain through extortion.
Goals & Targeting
LunaLock's primary objectives revolve around organizational and financial gains through ransomware activities. Their targeting strategy focuses on creative and digital sectors, likely due to the high value of intellectual property and the potential for severe reputational damage when stolen data is involved. By selecting specific victims within these industries, LunaLock aims to maximize leverage and minimize detection risk. The choice of sectors and countries seems calculated, potentially reflecting operational capabilities or strategic interests that are still under development.
Enhanced Description
LunaLock has emerged as a notable threat actor in the cybercriminal landscape, operating with marked precision in targeting creative and digital platforms. Since their inception in September 2025, they have successfully compromised an illustrator marketplace and a Mexican ISP, showcasing their ability to penetrate sectors where intellectual property is highly valued. Their modus operandi involves leveraging stolen data as leverage for extortion, as evidenced by threats to submit artwork samples to AI training repositories if ransoms are not met. These tactics indicate a strategic approach to maximize the psychological impact on victims while ensuring financial gain through ransomware distribution.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LunaLock's known campaigns include at least one successful phishing attack with ransomware distribution. They have demonstrated the ability to target specific sectors, including creative industries and ISPs. Notably, their campaign involving an illustrator marketplace highlights their understanding of data leverage for extortion. Despite emerging in September 2025, LunaLock's relatively short operational timeline indicates early-stage activity that may evolve over time.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in LunaLock's intelligence is moderate to low due to limited operational history and specific targeting details. The threat actor's emergence in late September 2025 suggests they may still be refining their methods. Key gaps include an unclear geographic focus, unelaborated tools, and limited campaign information beyond the known victims.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics