ATT&CKReferencesBitdefender LuminousMoth July 2021

Bitdefender LuminousMoth July 2021

Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1030
Data Transfer Size Limits
GroupLuminousMoth

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

T1033
System Owner/User Discovery
GroupLuminousMoth

LuminousMoth has used a malicious DLL to collect the username from compromised hosts.

T1053.005
Scheduled Task
GroupLuminousMoth

LuminousMoth has created scheduled tasks to establish persistence for their tools.

T1083
File and Directory Discovery
GroupLuminousMoth

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1091
Replication Through Removable Media
GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1105
Ingress Tool Transfer
GroupLuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1112
Modify Registry
GroupLuminousMoth

LuminousMoth has used malware that adds Registry keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLuminousMoth

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1557.002
ARP Cache Poisoning
GroupLuminousMoth

LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website.

T1560
Archive Collected Data
GroupLuminousMoth

LuminousMoth has manually archived stolen files from victim machines before exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupLuminousMoth

LuminousMoth has exfiltrated data to Google Drive.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1587.001
Malware
GroupLuminousMoth

LuminousMoth has used unique malware for information theft and exfiltration.

T1588.001
Malware
GroupLuminousMoth

LuminousMoth has obtained and used malware such as Cobalt Strike.

T1588.002
Tool
GroupLuminousMoth

LuminousMoth has obtained an ARP spoofing tool from GitHub.

T1608.004
Drive-by Target
GroupLuminousMoth

LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.