HomeSecurityLunaLock ransomware attacks artists

LunaLock ransomware attacks artists

Security researchers discovered the new LunaLock ransomwarein early September 2025, which appears to target freelance illustrators and digital artists.

LunaLock ransomware artists

Using compromised credentials and social engineering, the team behind LunaLock has focused on a niche market— Artists & Clients—where freelance creators exchange custom commissions.

The initial attack typically begins with spear-phishing campaigns disguised as entitlement notifications, luring victims into downloading infected 'invoice' attachments. Once executed, the payload begins reconnaissance of art assets and customer databases, while preparing for rapid encryption.

See also: Hackers abuse Amazon SES for phishing attacks

LunaLock ransomware: Targeting artists

VenariX analysts identified LunaLock's deployment after correlating unusual outgoing HTTP requests from artist workstations with a mass file encryption. Their telemetry revealed that the malware extracts user tokens from Microsoft Teams and Slack applications , allowing lateral movement to shared design repositories and project management platforms.

Victims report encrypted source PSD and AI files, whose names are appended with the extension '.lunalock'. Along with the files, a ransom note appears demanding payment in Monero.

It is worth noting that the ransomware's impact extends beyond data encryption: stolen artworks are exported to a remote command and control server before victims receive the decryption keys.

See also: GhostAction campaign steals 3325 secrets in GitHub attack

Publicly disclosed samples show a modular architecture of LunaLock ransomware with plugins for network propagation, credential theft , and evasion of endpoint detection systems. A notable innovation is the inclusion of a minified JavaScript module that disables Windows Defender real-time scanning processes.

LunaLock ransomware attacks artists

An in-depth analysis of the LunaLock ransomware infection mechanism also reveals a custom loader that dynamically resolves Win32 API calls to avoid static analysis. During execution, the loader parses its PE header to locate the IAT and reconstructs the API names using an XOR-based encryption key. After the resolve function completes, the main payload is mapped to memory without ever touching disk.

// Dynamic API resolution snippet BYTE obfName[] = {0x5F,0x23,0xA7,0x19}; // XOR key for (DWORD i = 0; i < nameLen; ++i) { nameBuf[i] = obfName[i] ^ encName[i]; } HMODULE hMod = LoadLibraryA("kernel32.dll"); FARPROC pFunc = GetProcAddress(hMod, nameBuf);

After resolution, LunaLock establishes persistence by creating a hidden Scheduled Task named 'SysUpdate', ensuring execution on every reboot. The loader then updates the C2 server via HTTPS, confirming successful deployment before initiating AES-256 encryption on mapped network drives.

Artists: An unusual target

LunaLock ransomware, as described, reveals a worrying shift in the cyberattack ecosystem: the targeted exploitation of creative communities and freelancers. Until now, most ransomware campaigns have targeted large organizations, healthcare businesses or public services, where attackers could extort large sums of money. LunaLock shows how cybercriminals are experimenting with more “vulnerable” markets – such as independent artists – knowing that they often lack specialized security knowledge or organized backup policies.

See also: Salesloft Drift attack linked to GitHub breach

LunaLock ransomware attacks artists

The choice of this market is not accidental. Illustrators and digital creators rely on valuable project files (PSD, AI, etc.), which are not just data, but intellectual property and professional capital. A damaged or stolen file can mean canceled orders, loss of income or even a reputational blow. Therefore, even if the ransom amounts are smaller compared to large attacks, the pressure on victims is extremely intense.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Furthermore, the tactic of exporting artworks before encryption introduces a double extortion model: not only the threat of losing access, but also the potential for the creations to be leaked or sold online. This touches on copyright issues and creates new ethical and legal dimensions, especially in markets where commissions are based on trust.

Finally, the technical sophistication of LunaLock, with dynamic API resolution, modular architecture and persistence mechanisms, proves that this is not “opportunistic” malware but an organized effort with significant know-how. The worrying thing is that such tools, if they target increasingly smaller professional communities, can deeply affect entire freelancing ecosystems, undermining their economic viability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS