Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupLuminousMoth | LuminousMoth has collected files and data from compromised machines. |
| T1030 Data Transfer Size Limits |
GroupLuminousMoth | LuminousMoth has split archived files into multiple parts to bypass a 5MB limit. |
| T1033 System Owner/User Discovery |
GroupLuminousMoth | LuminousMoth has used a malicious DLL to collect the username from compromised hosts. |
| T1053.005 Scheduled Task |
GroupLuminousMoth | LuminousMoth has created scheduled tasks to establish persistence for their tools. |
| T1083 File and Directory Discovery |
GroupLuminousMoth | LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives. |
| T1091 Replication Through Removable Media |
GroupLuminousMoth | LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| T1105 Ingress Tool Transfer |
GroupLuminousMoth | LuminousMoth has downloaded additional malware and tools onto a compromised host. |
| T1112 Modify Registry |
GroupLuminousMoth | LuminousMoth has used malware that adds Registry keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLuminousMoth | LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`. |
| T1557.002 ARP Cache Poisoning |
GroupLuminousMoth | LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website. |
| T1560 Archive Collected Data |
GroupLuminousMoth | LuminousMoth has manually archived stolen files from victim machines before exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLuminousMoth | LuminousMoth has exfiltrated data to Google Drive. |
| T1574.001 DLL |
GroupLuminousMoth | LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware. |
| T1587.001 Malware |
GroupLuminousMoth | LuminousMoth has used unique malware for information theft and exfiltration. |
| T1588.001 Malware |
GroupLuminousMoth | LuminousMoth has obtained and used malware such as Cobalt Strike. |
| T1588.002 Tool |
GroupLuminousMoth | LuminousMoth has obtained an ARP spoofing tool from GitHub. |
| T1608.004 Drive-by Target |
GroupLuminousMoth | LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.