LuminousMoth is a malware family/cluster used in cyber-espionage activity and referenced as operating alongside other implants such as PlugX and, in later reporting, CoolClient. The content directly associates LuminousMoth with spearphishing-based delivery, including emails containing malicious Dropbox download links, and with actor-controlled web redirection via ARP spoofing/ARP cache poisoning and HTML injection. Reported execution and persistence tradecraft includes DLL side-loading using legitimate executables such as winword.exe and igfxem.exe, Run key persistence under HKCU\Software\Microsoft\Windows\Current Version\Run, and scheduled tasks. LuminousMoth uses HTTP for command-and-control and is described as collecting files from victim systems, scanning user folders such as Documents, Desktop, and Downloads as well as other drives, manually archiving stolen files before exfiltration, and splitting archives to bypass a 5 MB transfer limit. Exfiltration has been observed both to actor C2 infrastructure and to Google Drive; one exfiltration component was disguised as ZoomVideoApp.exe. Additional behaviors mentioned in the content include propagation to removable USB drives via malicious DLLs, storage of malicious binaries in hidden USB directories, use of a valid digital certificate/digital signature for some malware, downloading additional tools such as Cobalt Strike, and use of a post-exploitation tool to steal Chrome cookies. The content also notes reporting that CoolClient was deployed as a secondary backdoor alongside LuminousMoth infections, and Kaspersky noted code-level similarities between a Mustang Panda browser credential stealer and a cookie stealer used by LuminousMoth, suggesting possible tool sharing. Extra findings in the content suggest a connection between LuminousMoth and Mustang Panda. Victim geography explicitly mentioned in the supporting content includes Myanmar and Thailand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
"Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe"; numerous other examples describe malware/tools that "modify registry keys/values" for persistence, configuration storage, defense evasion, and credential access.
“DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files… actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe … has used legitimate names and locations for files to evade defenses.”
"Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe"; numerous other examples describe malware/tools that "modify registry keys/values" for persistence, configuration storage, defense evasion, and credential access.
Multiple malware and threat groups are described as collecting the current username or user/session details, frequently via built-in OS commands/APIs (e.g., "whoami", "query user", "quser", GetUserNameA) and via WMI/PowerShell.
"...has a command to retrieve metadata for files on disk as well as a command to list the current working directory." / "...can list files and directories." / "...used the following commands... to obtain information about files and directories: dir c:\ >> %temp%\download ..."
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a co-occurring infection with COOLCLIENT; content notes code-level similarities between a browser cookie stealer analyzed by Kaspersky and a cookie stealer used by LuminousMoth, suggesting tool sharing.
Referenced as a custom malware family used by Mustang Panda; specific capabilities are not described in the provided content.
Backdoor mentioned as co-deployed alongside CoolClient by Mustang Panda.
Malware family linked in the report to HoneyMyte operations; its cookie stealer code shows similarities to HoneyMyte’s browser credential stealer, suggesting tool reuse/shared codebase.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.