lunalock is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 2 public victims claimed by this operator between September 2, 2025 and September 16, 2025. LunaLock is a recently emerged ransomware group first observed in September 2025, appearing to be financially motivated based on their limited operational footprint. The group's country of origin and potential affiliations remain unknown due to their recent emergence and limited public documentation. With only two documented victims to date, LunaLock appears to primarily target telecommunications infrastructure, with attacks recorded in the United States and Mexico, though their specific attack methodology, encryption techniques, and whether they employ data exfiltration tactics have not been publicly documented by major security research organizations. No notable high-profile campaigns or significant ransomware demands have been reported for this group, and no law enforcement actions have been publicly disclosed. LunaLock appears to remain active as of late 2025, though their limited victim count and recent emergence make it difficult to assess their long-term operational capabilities or intentions.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.