ATT&CKGroupsLuminousMoth

LuminousMoth

G1014

Threat group.View on attack.mitre.org

About this group

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1005
Data from Local System

LuminousMoth has collected files and data from compromised machines.

T1030
Data Transfer Size Limits

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

T1033
System Owner/User Discovery

LuminousMoth has used a malicious DLL to collect the username from compromised hosts.

T1036.005
Match Legitimate Resource Name or Location

LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`.

T1041
Exfiltration Over C2 Channel

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1053.005
Scheduled Task

LuminousMoth has created scheduled tasks to establish persistence for their tools.

T1071.001
Web Protocols

LuminousMoth has used HTTP for C2.

T1083
File and Directory Discovery

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1091
Replication Through Removable Media

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1105
Ingress Tool Transfer

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1112
Modify Registry

LuminousMoth has used malware that adds Registry keys for persistence.

T1204.001
Malicious Link

LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing.

T1539
Steal Web Session Cookie

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

T1547.001
Registry Run Keys / Startup Folder

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1553.002
Code Signing

LuminousMoth has signed their malware with a valid digital signature.

View all 28 procedure examples

Software2

Campaigns0

None recorded.

References2

  1. Bitdefender LuminousMoth July 2021 Open source
    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
  2. Kaspersky LuminousMoth July 2021 Open source
    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.