G1014: LuminousMoth
MITRE ATT&CK G1014: LuminousMoth Group details, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
LuminousMoth matters because ATT&CK links this espionage group to behaviors that can expose sensitive data, sustain access, and blend command-and-control or exfiltration into normal web and cloud activity. The supplied ATT&CK record describes targeting of high-profile organizations, including government entities, in Southeast Asia, and notes reported similarities with Mustang Panda; those details should be treated as intelligence context, not proof of current exposure. For leaders, the practical value is to validate whether email/link defenses, endpoint persistence monitoring, removable media controls, cloud-storage egress visibility, and incident response evidence collection can withstand this style of intrusion activity.
Executive priority
Prioritize this as a data protection and resilience question rather than a single malware question. The related techniques include spearphishing links, removable media replication, local data collection, archiving, C2 over web protocols, exfiltration over C2, and exfiltration to cloud storage. Executives should ask whether the organization can prove visibility across endpoints, email, identity/session activity, web egress, and sanctioned or unsanctioned cloud storage use. For regulated or government-adjacent environments, this also supports audit evidence around monitoring, access control, data loss prevention, and incident response readiness.
Technical view
ATT&CK does not provide a dedicated detection section for LuminousMoth, so SOC validation should be driven by the mapped software and techniques. Focus on Windows persistence and evasion behaviors tied to Scheduled Task, Registry Run Keys/Startup Folder, Modify Registry, DLL abuse, hidden files/directories, and legitimate-looking names or locations. Validate monitoring for PlugX and Cobalt Strike where those tools are relevant to local detections, while avoiding tool-name-only logic because Cobalt Strike is also used for authorized adversary simulation. For collection and exfiltration, correlate file and directory discovery, local data access, archive creation, unusual chunked transfers, web-protocol C2 patterns, and cloud-storage uploads. Include removable media telemetry because ATT&CK maps LuminousMoth to replication through removable media, which can be material for disconnected or segmented environments.
Likely telemetry
- Email security and web proxy logs for spearphishing links and user click-through activity
- Endpoint process creation, command-line, module load, file creation, and persistence telemetry
- Windows Task Scheduler, Registry, Run Key, and Startup Folder change logs
- File system telemetry for hidden files, suspicious archives, renamed or legitimate-looking binaries, and local data staging
- EDR or host telemetry for DLL abuse and signed or suspicious binaries
Detection direction
- Build detections around behavior chains, not only indicators: phishing link activity followed by tool transfer, persistence creation, discovery, collection, archive creation, and outbound transfer is higher value than any single event.
- Tune Windows detections for scheduled task creation, Run Key or Startup Folder persistence, registry modification, hidden files, suspicious DLL loading, and executables placed or named to resemble legitimate resources.
- Correlate discovery commands or file enumeration with subsequent archive creation and outbound web or cloud-storage traffic.
- Review cloud-storage egress baselines; exfiltration to common services can be missed when those services are broadly allowed for business use.
- Treat Cobalt Strike detections carefully: distinguish approved security testing infrastructure from unexpected beacons or post-exploitation behavior.
Mitigation priorities
- Reduce initial access risk by strengthening phishing-link protections, user reporting workflows, browser isolation or safe-link controls where used, and rapid triage of suspicious click events.
- Harden endpoint persistence paths: monitor and restrict unauthorized scheduled tasks, Registry Run Keys, Startup Folder entries, and suspicious registry modifications.
- Control removable media use according to business need, with logging and restrictions for sensitive or disconnected environments.
- Improve egress governance for web protocols and cloud storage: define allowed services, inspect or log proxy activity where appropriate, and alert on unusual upload patterns or destinations.
- Protect identity and session material by limiting browser/session exposure, enforcing strong authentication, and ensuring SaaS/session activity is logged for investigation.
Additional notes and limits
The ATT&CK object identifies LuminousMoth as a Chinese-speaking cyber espionage group active since at least October 2020, with reported targeting of high-profile organizations including government entities in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. ATT&CK also notes that some researchers have concluded there is a connection to Mustang Panda based on similar targeting, TTPs, and infrastructure overlaps. This take uses the supplied ATT&CK relationships to PlugX, Cobalt Strike, and the listed techniques to frame defensive validation priorities.
Platforms and tactics are not specified on the intrusion-set object itself, and no official detection text is provided. Platform references in this take come only from related software and technique records. The supplied data supports defensive prioritization and telemetry validation, but not claims of current exploitation, specific victim exposure, guaranteed detection coverage, or definitive attribution beyond the official ATT&CK description.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
LuminousMoth
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1539 | Steal Web Session Cookie | This object uses Steal Web Session Cookie. |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | This object uses Exfiltration to Cloud Storage. |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | This object uses Spearphishing Link. |
| Enterprise | T1588.001 | MalwareSub-technique | This object uses Malware. |
| Enterprise | T1030 | Data Transfer Size Limits | This object uses Data Transfer Size Limits. |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | This object uses Hidden Files and Directories. |
| Enterprise | T1608.001 | Upload MalwareSub-technique | This object uses Upload Malware. |
| Enterprise | T1091 | Replication Through Removable Media | This object uses Replication Through Removable Media. |
| Enterprise | T1041 | Exfiltration Over C2 Channel | This object uses Exfiltration Over C2 Channel. |
| Enterprise | T1608.004 | Drive-by TargetSub-technique | This object uses Drive-by Target. |
| Enterprise | T1608.005 | Link TargetSub-technique | This object uses Link Target. |
| Enterprise | T1587.001 | MalwareSub-technique | This object uses Malware. |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | This object uses Web Protocols. |
| Enterprise | T1105 | Ingress Tool Transfer | This object uses Ingress Tool Transfer. |
| Enterprise | T1557.002 | ARP Cache PoisoningSub-technique | This object uses ARP Cache Poisoning. |
| Enterprise | T1588.002 | ToolSub-technique | This object uses Tool. |
| Enterprise | T1005 | Data from Local System | This object uses Data from Local System. |
| Enterprise | T1204.001 | Malicious LinkSub-technique | This object uses Malicious Link. |
| Enterprise | T1574.001 | DLLSub-technique | This object uses DLL. |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | This object uses Registry Run Keys / Startup Folder. |
| Enterprise | T1083 | File and Directory Discovery | This object uses File and Directory Discovery. |
| Enterprise | T1033 | System Owner/User Discovery | This object uses System Owner/User Discovery. |
| Enterprise | T1560 | Archive Collected Data | This object uses Archive Collected Data. |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | This object uses Match Legitimate Resource Name or Location. |
| Enterprise | T1112 | Modify Registry | This object uses Modify Registry. |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | This object uses Scheduled Task. |
| Enterprise | T1588.004 | Digital CertificatesSub-technique | This object uses Digital Certificates. |
| Enterprise | T1553.002 | Code SigningSub-technique | This object uses Code Signing. |
Groups, software, and campaigns
S0013: PlugX
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | 1d14c20bca59… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [2]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [3]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [4]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [5]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [6]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [7]mitre-attackG1014Open source URL
- [8]mitre-attackG1014Open source URL
- [9]mitre-attackG1014Open source URL
- [10]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [11]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [12]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [13]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [14]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [15]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [16]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [17]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [18]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [19]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [20]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [21]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [22]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [23]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [24]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [25]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [26]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [27]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [28]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [29]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [30]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [31]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [32]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [33]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [34]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [35]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [36]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [37]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [38]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [39]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [40]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [41]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [42]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [43]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [44]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [45]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [46]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [47]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [48]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [49]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [50]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [51]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [52]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [53]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [54]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [55]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [56]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [57]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [58]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [59]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [60]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [61]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [62]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [63]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [64]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [65]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [66]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [67]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [68]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [69]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [70]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [71]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [72]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [73]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [74]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [75]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [76]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [77]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [78]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [79]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [80]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [81]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [82]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [83]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [84]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [85]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL - [86]Bitdefender LuminousMoth July 2021
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Open source URL - [87]Kaspersky LuminousMoth July 2021
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
