A self-described hacktivist collective calling itself LunarisSec has published a manifesto opposing the European Union’s “Chat Control” surveillance legislation, followed by a message suggesting unspecified system access.

What Happened
A hacktivist group identifying itself as LunarisSec has publicly targeted the European Union’s controversial “Chat Control” proposal, publishing a manifesto on Telegram that combines political demands with implicit threats of retaliation.
In a post dated July 27, LunarisSec, which identifies with Algeria in its channel branding, issued what it called an “ultimatum” over the EU’s mass-surveillance initiative known as Chat Control. The message outlined four core demands: the permanent abandonment of both Chat Control 1.0 and 2.0, constitutional-level protection for end-to-end encryption across the EU, full transparency on data-sharing agreements with third parties, and the creation of an independent body to oversee data collection practices.
The group framed itself as a defender of digital privacy rather than a criminal actor, arguing that any backdoor built into encrypted communications for law enforcement purposes would also expose ordinary users to exploitation by cybercriminals.

Who Is Affected
The demands are directed at EU policymakers and institutions involved in drafting and advancing the Chat Control legislation. By extension, the group frames the “affected” parties as all EU citizens who rely on encrypted messaging services, should the proposal move forward.
Follow-Up Post and Unverified Claims
A day later, on July 28, LunarisSec published a second message that was more provocative in tone, mocking unnamed parties over allegedly weak security practices and reiterating opposition to Chat Control. The post was accompanied by images showing terminal-style or log-style text overlaid with the group’s logo, which could be interpreted as an implication of system access or reconnaissance activity.
Threat Actor Background
LunarisSec presents itself as a hacktivist collective motivated by opposition to surveillance legislation rather than financial gain. The group’s branding – including a logo styled after historic activist imagery and hashtags referencing Algeria – suggests an attempt to position itself within the broader hacktivist tradition of politically motivated cyber campaigns. No technical indicators, malware samples, or infrastructure details have been published that would allow independent attribution or capability assessment.

Potential Impact
If the group’s claims of access or capability are eventually substantiated, the impact could range from data exposure to disruption of systems tied to EU institutions or affiliated entities. However, absent verified evidence, the more immediate impact is reputational and political: the campaign adds public pressure to an already contentious legislative debate over Chat Control, which has faced sustained criticism from privacy advocates, technologists, and some EU member states over its implications for end-to-end encryption.
Response and Mitigation
No official EU institution has publicly responded to LunarisSec’s statements at the time of writing. Organizations and individuals following the Chat Control debate are advised to rely on official EU communications for the legislative status of the proposal, rather than claims made on hacktivist-affiliated Telegram channels.
Conclusion
LunarisSec’s public ultimatum reflects the ongoing friction between privacy advocates and EU lawmakers over the Chat Control proposal. While the group’s political demands are clearly stated, its implied claims of technical access remain unverified, and further developments will need independent confirmation before any security impact can be assessed. CyberAsia.io will continue monitoring the situation for updates.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.