Threat group.View on attack.mitre.org
LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
LuminousMoth has collected files and data from compromised machines. |
| T1030 Data Transfer Size Limits |
LuminousMoth has split archived files into multiple parts to bypass a 5MB limit. |
| T1033 System Owner/User Discovery |
LuminousMoth has used a malicious DLL to collect the username from compromised hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`. |
| T1041 Exfiltration Over C2 Channel |
LuminousMoth has used malware that exfiltrates stolen data to its C2 server. |
| T1053.005 Scheduled Task |
LuminousMoth has created scheduled tasks to establish persistence for their tools. |
| T1071.001 Web Protocols |
LuminousMoth has used HTTP for C2. |
| T1083 File and Directory Discovery |
LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives. |
| T1091 Replication Through Removable Media |
LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| T1105 Ingress Tool Transfer |
LuminousMoth has downloaded additional malware and tools onto a compromised host. |
| T1112 Modify Registry |
LuminousMoth has used malware that adds Registry keys for persistence. |
| T1204.001 Malicious Link |
LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing. |
| T1539 Steal Web Session Cookie |
LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser. |
| T1547.001 Registry Run Keys / Startup Folder |
LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`. |
| T1553.002 Code Signing |
LuminousMoth has signed their malware with a valid digital signature. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.