LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1014: LuminousMoth

MITRE ATT&CK G1014: LuminousMoth Group details, with detection guidance, relationships and mapped CVEs.

EnterpriseG1014GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

LuminousMoth matters because ATT&CK links this espionage group to behaviors that can expose sensitive data, sustain access, and blend command-and-control or exfiltration into normal web and cloud activity. The supplied ATT&CK record describes targeting of high-profile organizations, including government entities, in Southeast Asia, and notes reported similarities with Mustang Panda; those details should be treated as intelligence context, not proof of current exposure. For leaders, the practical value is to validate whether email/link defenses, endpoint persistence monitoring, removable media controls, cloud-storage egress visibility, and incident response evidence collection can withstand this style of intrusion activity.

Executive priority

Prioritize this as a data protection and resilience question rather than a single malware question. The related techniques include spearphishing links, removable media replication, local data collection, archiving, C2 over web protocols, exfiltration over C2, and exfiltration to cloud storage. Executives should ask whether the organization can prove visibility across endpoints, email, identity/session activity, web egress, and sanctioned or unsanctioned cloud storage use. For regulated or government-adjacent environments, this also supports audit evidence around monitoring, access control, data loss prevention, and incident response readiness.

Technical view

ATT&CK does not provide a dedicated detection section for LuminousMoth, so SOC validation should be driven by the mapped software and techniques. Focus on Windows persistence and evasion behaviors tied to Scheduled Task, Registry Run Keys/Startup Folder, Modify Registry, DLL abuse, hidden files/directories, and legitimate-looking names or locations. Validate monitoring for PlugX and Cobalt Strike where those tools are relevant to local detections, while avoiding tool-name-only logic because Cobalt Strike is also used for authorized adversary simulation. For collection and exfiltration, correlate file and directory discovery, local data access, archive creation, unusual chunked transfers, web-protocol C2 patterns, and cloud-storage uploads. Include removable media telemetry because ATT&CK maps LuminousMoth to replication through removable media, which can be material for disconnected or segmented environments.

Likely telemetry

  • Email security and web proxy logs for spearphishing links and user click-through activity
  • Endpoint process creation, command-line, module load, file creation, and persistence telemetry
  • Windows Task Scheduler, Registry, Run Key, and Startup Folder change logs
  • File system telemetry for hidden files, suspicious archives, renamed or legitimate-looking binaries, and local data staging
  • EDR or host telemetry for DLL abuse and signed or suspicious binaries

Detection direction

  • Build detections around behavior chains, not only indicators: phishing link activity followed by tool transfer, persistence creation, discovery, collection, archive creation, and outbound transfer is higher value than any single event.
  • Tune Windows detections for scheduled task creation, Run Key or Startup Folder persistence, registry modification, hidden files, suspicious DLL loading, and executables placed or named to resemble legitimate resources.
  • Correlate discovery commands or file enumeration with subsequent archive creation and outbound web or cloud-storage traffic.
  • Review cloud-storage egress baselines; exfiltration to common services can be missed when those services are broadly allowed for business use.
  • Treat Cobalt Strike detections carefully: distinguish approved security testing infrastructure from unexpected beacons or post-exploitation behavior.

Mitigation priorities

  • Reduce initial access risk by strengthening phishing-link protections, user reporting workflows, browser isolation or safe-link controls where used, and rapid triage of suspicious click events.
  • Harden endpoint persistence paths: monitor and restrict unauthorized scheduled tasks, Registry Run Keys, Startup Folder entries, and suspicious registry modifications.
  • Control removable media use according to business need, with logging and restrictions for sensitive or disconnected environments.
  • Improve egress governance for web protocols and cloud storage: define allowed services, inspect or log proxy activity where appropriate, and alert on unusual upload patterns or destinations.
  • Protect identity and session material by limiting browser/session exposure, enforcing strong authentication, and ensuring SaaS/session activity is logged for investigation.
Additional notes and limits

The ATT&CK object identifies LuminousMoth as a Chinese-speaking cyber espionage group active since at least October 2020, with reported targeting of high-profile organizations including government entities in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. ATT&CK also notes that some researchers have concluded there is a connection to Mustang Panda based on similar targeting, TTPs, and infrastructure overlaps. This take uses the supplied ATT&CK relationships to PlugX, Cobalt Strike, and the listed techniques to frame defensive validation priorities.

Platforms and tactics are not specified on the intrusion-set object itself, and no official detection text is provided. Platform references in this take come only from related software and technique records. The supplied data supports defensive prioritization and telemetry validation, but not claims of current exploitation, specific victim exposure, guaranteed detection coverage, or definitive attribution beyond the official ATT&CK description.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

LuminousMoth

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

28 rows
DomainIDNameRelationship / procedure
EnterpriseT1539Steal Web Session CookieThis object uses Steal Web Session Cookie.
EnterpriseT1567.002Exfiltration to Cloud StorageSub-techniqueThis object uses Exfiltration to Cloud Storage.
EnterpriseT1566.002Spearphishing LinkSub-techniqueThis object uses Spearphishing Link.
EnterpriseT1588.001MalwareSub-techniqueThis object uses Malware.
EnterpriseT1030Data Transfer Size LimitsThis object uses Data Transfer Size Limits.
EnterpriseT1564.001Hidden Files and DirectoriesSub-techniqueThis object uses Hidden Files and Directories.
EnterpriseT1608.001Upload MalwareSub-techniqueThis object uses Upload Malware.
EnterpriseT1091Replication Through Removable MediaThis object uses Replication Through Removable Media.
EnterpriseT1041Exfiltration Over C2 ChannelThis object uses Exfiltration Over C2 Channel.
EnterpriseT1608.004Drive-by TargetSub-techniqueThis object uses Drive-by Target.
EnterpriseT1608.005Link TargetSub-techniqueThis object uses Link Target.
EnterpriseT1587.001MalwareSub-techniqueThis object uses Malware.
EnterpriseT1071.001Web ProtocolsSub-techniqueThis object uses Web Protocols.
EnterpriseT1105Ingress Tool TransferThis object uses Ingress Tool Transfer.
EnterpriseT1557.002ARP Cache PoisoningSub-techniqueThis object uses ARP Cache Poisoning.
EnterpriseT1588.002ToolSub-techniqueThis object uses Tool.
EnterpriseT1005Data from Local SystemThis object uses Data from Local System.
EnterpriseT1204.001Malicious LinkSub-techniqueThis object uses Malicious Link.
EnterpriseT1574.001DLLSub-techniqueThis object uses DLL.
EnterpriseT1547.001Registry Run Keys / Startup FolderSub-techniqueThis object uses Registry Run Keys / Startup Folder.
EnterpriseT1083File and Directory DiscoveryThis object uses File and Directory Discovery.
EnterpriseT1033System Owner/User DiscoveryThis object uses System Owner/User Discovery.
EnterpriseT1560Archive Collected DataThis object uses Archive Collected Data.
EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-techniqueThis object uses Match Legitimate Resource Name or Location.
EnterpriseT1112Modify RegistryThis object uses Modify Registry.
EnterpriseT1053.005Scheduled TaskSub-techniqueThis object uses Scheduled Task.
EnterpriseT1588.004Digital CertificatesSub-techniqueThis object uses Digital Certificates.
EnterpriseT1553.002Code SigningSub-techniqueThis object uses Code Signing.
Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
1d14c20bca59ab91...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle1d14c20bca59…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  2. [2]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  3. [3]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  4. [4]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  5. [5]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  6. [6]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  7. [7]
    mitre-attackG1014
    Open source URL
  8. [8]
    mitre-attackG1014
    Open source URL
  9. [9]
    mitre-attackG1014
    Open source URL
  10. [10]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  11. [11]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  12. [12]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  13. [13]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  14. [14]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  15. [15]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  16. [16]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  17. [17]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  18. [18]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  19. [19]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  20. [20]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  21. [21]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  22. [22]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  23. [23]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  24. [24]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  25. [25]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  26. [26]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  27. [27]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  28. [28]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  29. [29]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  30. [30]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  31. [31]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  32. [32]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  33. [33]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  34. [34]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  35. [35]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  36. [36]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  37. [37]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  38. [38]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  39. [39]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  40. [40]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  41. [41]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  42. [42]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  43. [43]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  44. [44]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  45. [45]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  46. [46]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  47. [47]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  48. [48]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  49. [49]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  50. [50]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  51. [51]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  52. [52]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  53. [53]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  54. [54]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  55. [55]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  56. [56]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  57. [57]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  58. [58]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  59. [59]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  60. [60]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  61. [61]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  62. [62]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  63. [63]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  64. [64]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  65. [65]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  66. [66]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  67. [67]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  68. [68]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  69. [69]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  70. [70]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  71. [71]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  72. [72]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  73. [73]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  74. [74]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  75. [75]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  76. [76]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  77. [77]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  78. [78]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  79. [79]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  80. [80]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  81. [81]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  82. [82]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  83. [83]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  84. [84]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  85. [85]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  86. [86]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  87. [87]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.