LuminousMoth

MITRE ATT&CK: G1014 View on attack.mitre.org

Aliases: LuminousMoth

First seen
2020-10-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:30:40

Targeted industries: government-and-public-sector

Targeted regions: country_code:mm country_code:ph country_code:th

Context

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.

Detection coverage

  • 154 YARA rules
  • 452 Sigma rules

Malware & tools used

  • Exfiltration to Cloud Storage (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Malware (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Upload Malware (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Drive-by Target (attack-pattern)
  • Link Target (attack-pattern)
  • Malware (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • ARP Cache Poisoning (attack-pattern)
  • Tool (attack-pattern)
  • Data from Local System (attack-pattern)
  • Malicious Link (attack-pattern)
  • DLL (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Modify Registry (attack-pattern)
  • Scheduled Task (attack-pattern)

Reports & references

  • MITRE ATT&CK — G1014 (report)
  • Kaspersky — 103332 (report)
  • bitdefender.com — Luminousmoth Plugx File Exfiltration And Persistence Revisited (report)

External references