NEW: Group Profiler — instant APT intel lookup. Try it →

LuminousMoth

G1014 China Espionage MITRE ATT&CK →

Overview

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.

Naming & attribution

LuminousMoth is tracked under 1 names across the industry. It uses 28 documented ATT&CK techniques — more than 62% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1557.002 ARP Cache Poisoning — used by 2 of 174 groups
  • T1608.005 Link Target — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Patchwork — 14 shared techniques (25% overlap)
  • Confucius — 9 shared techniques (24% overlap)
  • FIN7 — 17 shared techniques (22% overlap)
  • WIRTE — 9 shared techniques (20% overlap)
  • Mustang Panda China — 18 shared techniques (19% overlap)
  • APT32 Vietnam — 17 shared techniques (19% overlap)

Targets

Civil society

Regions

Germany · United States

TTPs — 28 techniques across 12 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Tools & malware (2)

PlugX · Cobalt Strike

Reporting (2)