Colton Ray Grubbs, a Kentucky man accused of creating and selling the LuminosityLink remote access trojan, pleaded guilty to authoring, marketing, and distributing malware that prosecutors said enabled unauthorized access to victims’ computers. Sold from 2015 through online forums under the alias "KFC Watermelon," LuminosityLink was promoted as a remote administration tool but was widely used to steal information, log keystrokes, disable security software, and activate webcams. Prosecutors said Grubbs also tried to conceal evidence before an FBI raid by removing hard drives and moving more than 114 bitcoin to new addresses.
The plea followed broader international enforcement and industry tracking of LuminosityLink’s spread. Europol said the malware had been sold to more than 8,600 customers and used against tens of thousands of computers across 78 countries, while Palo Alto Networks researchers previously analyzed the malware’s encrypted configuration and extracted data from roughly 14,700 samples out of nearly 18,000 collected. That research tied LuminosityLink to about 50,000 attempted infections observed against customers and documented its use as a full-featured backdoor with configurable command-and-control domains, ports, and surveillance capabilities.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Three days after learning of the planned FBI search, Grubbs transferred more than 114 bitcoin from his LuminosityLink bitcoin address into six new bitcoin addresses, according to the plea agreement.
According to the plea agreement, on July 10, 2017, Grubbs learned the FBI was about to raid his apartment and hid the phone and debit card tied to his Bitcoin account while removing hard drives from his computer and apartment.
By mid-2017, Europol said LuminosityLink had been sold to more than 8,600 customers and used against tens of thousands of computers across 78 countries.
Federal prosecutors said Colton Ray Grubbs began selling the LuminosityLink remote access tool in May 2015 under the alias "KFC Watermelon," marketing it via Hackforums.net for $40.
Colton Ray Grubbs pleaded guilty to conspiring to author, market, and distribute LuminosityLink and to knowingly assisting customers in using it to break into computers and steal information.
A Palo Alto Networks blog post linked the Skype account associated with "KFC Watermelon" to an email address tied to earlier RAT-related domain registrations, connecting LuminosityLink's operator to prior malware infrastructure.
Palo Alto Networks released research detailing how LuminosityLink stores and encrypts its configuration and reported extracting configurations from thousands of samples. The company also said it had observed about 50,000 attempted infections against its customers and was detecting related malware, domains, and C2 traffic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.