Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LuminousMoth

Description

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.(Citation: Kaspersky LuminousMoth July 2021)(Citation: Bitdefender LuminousMoth July 2021)

AI Analysis

· 1 week ago

Executive Summary

LuminousMoth is a suspected Chinese-speaking cyber espionage group active since October 2020, targeting government and military entities in Southeast Asia, including Myanmar, the Philippines, Thailand, and other regions. The group has been linked to Mustang Panda through overlapping network infrastructure and similar TTPs. LuminousMoth employs a range of advanced tools and techniques, including PlugX malware and Cobalt Strike, to conduct targeted attacks for intelligence gathering.

Goals & Targeting

LuminousMoth appears to be motivated by espionage objectives, likely seeking political or military intelligence from targeted governments. The group's focus on Southeast Asian countries suggests a strategic interest in regional geopolitical dynamics or potential collaboration with state-sponsored entities. Its victims include government agencies and institutions, indicating a focus on sensitive data collection.

Enhanced Description

LuminousMoth is a cyber espionage group primarily targeting government and military organizations in Southeast Asian countries such as Myanmar, the Philippines, Thailand, and others. The group has been observed using sophisticated tools such as PlugX malware and Cobalt Strike to compromise systems, establish persistence, and exfiltrate sensitive data. While LuminousMoth's exact origin remains unclear, there are indications of a potential connection to Mustang Panda due to shared targeting patterns and technical overlaps. The group's operations have raised concerns among security researchers, particularly regarding its ability to infiltrate high-value targets and maintain long-term access within targeted networks.

Key Capabilities

  • Espionage operations targeting government and military entities
  • Use of PlugX malware for入侵和持久化
  • Employment of Cobalt Strike for initial compromise and credential dumping
  • Phishing campaigns leveraging malicious links and Office document macros
  • Data exfiltration via cloud storage and C2 channels
  • Network persistence using registry modifications and startup folders

MITRE ATT&CK Tactics

Espionage
Initial Access
Defense Evasion
Credential Access
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1053.005: Scheduled Task
T1036.005: Match Legitimate Resource Name or Location
T1587.001: Malware
T1553.002: Code Signing
T1566.002: Spearphishing Link
T1574.001: DLL
T1005: Data from Local System
T1560: Archive Collected Data
T1112: Modify Registry
T1588.001: Malware
T1083: File and Directory Discovery
T1030: Data Transfer Size Limits
T1608.005: Link Target
T1041: Exfiltration Over C2 Channel
T1588.002: Tool
T1567.002: Exfiltration to Cloud Storage
T1557.002: ARP Cache Poisoning
T1071.001: Web Protocols
T1564.001: Hidden Files and Directories
T1204.001: Malicious Link
T1033: System Owner/User Discovery
T1539: Steal Web Session Cookie
T1588.004: Digital Certificates
T1608.001: Upload Malware
T1547.001: Registry Run Keys / Startup Folder
T1105: Ingress Tool Transfer

Software / Tooling

PlugX
Cobalt Strike

Campaigns & Victims

LuminousMoth's campaigns have been most active in Southeast Asia, with a particular focus on government and military targets. The group has demonstrated a patient attack cycle, including initial compromise, lateral movement within networks, and prolonged data collection before exfiltration. Notable operations tracked include targeted phishing attempts using malicious links and the deployment of PlugX malware for persistence and data theft.

IOC Patterns

  • Spear-phishing with malicious links targeting government entities
  • PlugX malware infections with registry-based persistence
  • Network traffic indicative of Cobalt Strike beacons
  • Phishing emails containing malicious Office document macros
  • Scheduled tasks or registry entries associated with PlugX activity
  • Exfiltration of data through cloud storage services or C2 channels

Recommended Actions

  • Implement strict monitoring for known LuminousMoth IOCs, such as malicious links and PlugX-related indicators.
  • Conduct regular security audits to detect potential network persistence mechanisms like registry modifications.
  • Enhance email security practices to prevent spear-phishing attacks with malicious links and macros.
  • Use endpoint detection and response (EDR) solutions to track Cobalt Strike-like activity and tool transfers.
  • Monitor cloud storage accounts for unauthorized data upload activities indicative of exfiltration.

Suggested Tags

APT
cyber espionage
Southeast Asia targeting
government/military targeting
PlugX malware

Confidence Assessment

High confidence in LuminousMoth's activity due to clear targeting patterns, toolset usage, and infrastructure overlaps with Mustang Panda. However, the lack of direct attribution to state-sponsored entities introduces some uncertainty. Additionally, the potential evolution of LuminousMoth's techniques beyond known IOCs remains a concern.

ATT&CK Techniques

Resource Development
7 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Bitdefender LuminousMoth July 2021 — Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
  2. Kaspersky LuminousMoth July 2021 — Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

Intel Summary

28

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

12

Tactics

Tags

APT
Government Targeting
cyber espionage
Southeast Asia targeting
government/military targeting
PlugX malware

Details

MITRE ID
G1014
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--b7f627e2-0817-4cd5-8d50-e75f8aa85cc6
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.