Threat actor
LuminousMoth
Last fetched
LuminousMoth is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 95 techniques.
Description
[LuminousMoth](https://attack.mitre.org/groups/G1014) is a Chinese-speaking cyber espionage group that has been active since at least October 2020. [LuminousMoth](https://attack.mitre.org/groups/G1014) has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between [LuminousMoth](https://attack.mitre.org/groups/G1014) and [Mustang Panda](https://attack.mitre.org/groups/G0129) based on similar targeting and TTPs, as well as network infrastructure overlaps.(Citation: Kaspersky LuminousMoth July 2021)(Citation: Bitdefender LuminousMoth July 2021)
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1071.001 · Web Protocols
- T1095 · Non-Application Layer Protocol
- T1102 · Web Service
- T1105 · Ingress Tool Transfer
- T1205 · Traffic Signaling
- T1219.001 · IDE Tunneling
- T1219.002 · Remote Desktop Software
- T1572 · Protocol Tunneling
- T1573.001 · Symmetric Cryptography
Discovery
- T1016 · System Network Configuration Discovery
- T1018 · Remote System Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1069.002 · Domain Groups
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1087.002 · Domain Account
- T1518 · Software Discovery
- T1622 · Debugger Evasion
- T1654 · Log Enumeration
Execution
- T1047 · Windows Management Instrumentation
- T1053.005 · Scheduled Task
- T1059 · Command and Scripting Interpreter
- T1059.001 · PowerShell
- T1059.003 · Windows Command Shell
- T1059.005 · Visual Basic
- T1059.007 · JavaScript
- T1072 · Software Deployment Tools
- T1106 · Native API
- T1129 · Shared Modules
- T1203 · Exploitation for Client Execution
- T1204.001 · Malicious Link
- T1204.002 · Malicious File
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
Resource Development
- T1583.001 · Domains
- T1583.006 · Web Services
- T1585.002 · Email Accounts
- T1586.002 · Email Accounts
- T1587.001 · Malware
- T1588.001 · Malware
- T1588.002 · Tool
- T1588.003 · Code Signing Certificates
- T1588.004 · Digital Certificates
- T1608 · Stage Capabilities
- T1608.001 · Upload Malware
- T1608.004 · Drive-by Target
- T1608.005 · Link Target
Stealth
- T1027 · Obfuscated Files or Information
- T1027.007 · Dynamic API Resolution
- T1027.012 · LNK Icon Smuggling
- T1027.016 · Junk Code Insertion
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.007 · Double File Extension
- T1036.008 · Masquerade File Type
- T1070 · Indicator Removal
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1140 · Deobfuscate/Decode Files or Information
- T1205 · Traffic Signaling
- T1218.004 · InstallUtil
- T1218.005 · Mshta
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
- T1622 · Debugger Evasion
- T1678 · Delay Execution
Attributed infrastructure
Infrastructure with a published ATTRIBUTED_TO link to LuminousMoth in WhisperGraph. Attribution is sparse graph-wide — this list is rarely exhaustive.
- black-popular.comHOSTNAME
- whatismybestthing.comHOSTNAME
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from LuminousMoth into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.