LuminousMoth APT

General News

Summary

APT-related campaigns are typically highly targeted with the cybercriminals tailoring the infection chain and the deployed malware threats to the specific entity they are aiming to breach. The file pretends to be a Word document but is a RAR archive containing two compromised DLL libraries and two legitimate executables tasked with side-loading the DLLs. It seems that the LuminousMoth attack campaign bears some striking similarities to operations carried out by an already established Chinese-related APT named HoneyMyte (Mustang Panda). Both groups display similar target criteria and TTPs (Tactics, Techniques, and Procedures) that include side-loading and the deployment of Cobalt Strike loaders. At the moment it cannot be conclusively determined if LuminousMoth is indeed a new hacker group or if it is a revamped version of HoneyMyte equipped with a new arsenal of malware tools.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M