ATT&CKReferencesKaspersky LuminousMoth July 2021

Kaspersky LuminousMoth July 2021

Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1036.005
Match Legitimate Resource Name or Location
GroupLuminousMoth

LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`.

T1041
Exfiltration Over C2 Channel
GroupLuminousMoth

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1071.001
Web Protocols
GroupLuminousMoth

LuminousMoth has used HTTP for C2.

T1083
File and Directory Discovery
GroupLuminousMoth

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1091
Replication Through Removable Media
GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1105
Ingress Tool Transfer
GroupLuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1112
Modify Registry
GroupLuminousMoth

LuminousMoth has used malware that adds Registry keys for persistence.

T1204.001
Malicious Link
GroupLuminousMoth

LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing.

T1539
Steal Web Session Cookie
GroupLuminousMoth

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

T1547.001
Registry Run Keys / Startup Folder
GroupLuminousMoth

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1553.002
Code Signing
GroupLuminousMoth

LuminousMoth has signed their malware with a valid digital signature.

T1564.001
Hidden Files and Directories
GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

T1566.002
Spearphishing Link
GroupLuminousMoth

LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1587.001
Malware
GroupLuminousMoth

LuminousMoth has used unique malware for information theft and exfiltration.

T1588.001
Malware
GroupLuminousMoth

LuminousMoth has obtained and used malware such as Cobalt Strike.

T1588.004
Digital Certificates
GroupLuminousMoth

LuminousMoth has used a valid digital certificate for some of their malware.

T1608.001
Upload Malware
GroupLuminousMoth

LuminousMoth has hosted malicious payloads on Dropbox.

T1608.005
Link Target
GroupLuminousMoth

LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.