LuminosityLink is a Windows remote access trojan (RAT) that emerged in 2015 as a low-cost commodity malware offering marketed as a remote administration utility. It was sold with a builder and server component that allowed purchasers to generate customized payloads and manage infected hosts at scale. Despite claims of legitimate administration use, LuminosityLink was widely used for unauthorized access and surveillance and became one of the more prevalent commodity RAT families of its period.
LuminosityLink provides full remote-control functionality over compromised systems and is associated with capabilities including keylogging, password theft, remote desktop access, shell interaction, webcam and microphone surveillance, downloading additional payloads, and broad post-compromise control. Reported feature sets also included persistence options, anti-analysis and anti-debugging settings, stealth features such as hiding files and directories, process injection behavior, and the ability to disable or evade security tooling. Some versions or advertised builds also included cryptocurrency mining and DDoS functionality, further underscoring its use as offensive malware rather than benign administration software.
The malware stores an embedded configuration in encrypted form within resources and has been observed using Base64-encoded data decrypted with AES-128 routines implemented through .NET cryptographic components. Analysts have documented configuration fields covering command-and-control settings, fallback connectivity, installation names, startup behavior, mutexes, build identifiers, and feature flags controlling persistence, silent execution, anti-malware behavior, anti-VM or anti-debugging checks, and backup startup behavior. Samples have also been observed obfuscated with ConfuserEx, and more heavily packed variants required memory-dump-based extraction to recover configuration data.
LuminosityLink was distributed through multiple criminal channels. High-confidence reporting ties it to phishing campaigns, including operations that used malicious attachments and links and, in at least one case, delivery through the Sundown exploit kit. It was also broadly sold on underground forums, enabling adoption by a wide range of actors. The malware has been observed in financially motivated activity, including Nigerian business email compromise operations, and in targeted intrusion ecosystems where actors used multiple commodity RAT families in parallel. It has also been linked to infrastructure used in campaigns with a Pakistan nexus, and reporting notes its use by the Pakistan-linked threat group COPPER FIELDSTONE alongside other commodity and custom RATs.
Operationally, LuminosityLink achieved broad global reach. Reporting has described tens of thousands of victim systems across dozens of countries and large volumes of attempted infections and unique samples collected over its active period. Activity declined sharply after its sales and licensing infrastructure went offline in 2017, with subsequent residual activity assessed to be driven in part by cracked copies that remained in circulation.
The malware is closely associated with its author, Colton Ray Grubbs, also known as "KFC Watermelon," who pleaded guilty to authoring, marketing, and distributing LuminosityLink and to assisting customers in using it for unauthorized access and information theft. Law-enforcement and industry reporting around the case helped establish LuminosityLink as a canonical example of commodity RAT malware sold as a service to a large criminal customer base.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2015-0359 Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux
CVE-2014-6332 .dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1
CVE-2014-0556 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249
CVE-2012-1876 Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory
CVE-2015-0313 Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux
The exploits being served by Sundown in this campaign include the Adobe Flash zero-days ... CVE-2015-0311 Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
the help forum on the luminosity[.]link site included an article about 'support regarding a third-party product (VPN, Crypter, etc)' ... 'I do cater to crypter coders now and are in contact with numerous developers to ensure Luminosity works great while crypted.'
Top Executable Names [1973] sysmon.exe [1831] client.exe [1254] helper.exe [1207] repair.exe [1087] winlogon.exe [509] svchost.exe
provides valuable information about with what hosts and ports the malware is configured to communicate
Crypto Currency Miner: Supports Scrypt, SHA256 and More, Custom Miner Support (For Alt Coins), Set amount of CPU to use, Supports CPU and GPU Mining
103 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a commodity RAT referenced in prior law-enforcement-focused research.
Remote access trojan used by Nigerian BEC actors to gain enhanced remote administration capabilities on victim hosts.
A popular remote access hacking tool used by many customers to gain unauthorized access to large numbers of computers worldwide.
A remote access trojan sold to thousands of buyers that enabled unauthorized access to victim computers, including viewing files, logging keystrokes, disabling security software, and activating webcams covertly.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.