logo

MUSTANG_PANDA__2021__Kaspersky-LuminousMothAPT-Sweeping-attackspdf_07-14-2021.pdf

ID: 9d52af03-7f73-4eef-9b45-10897356e166

STIX ID: report--9d52af03-7f73-4eef-9b45-10897356e166

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2021-09-07

Last Modified Date: 2021-09-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report profiles the LuminousMoth APT — a sophisticated, Chinese‑language affiliated campaign active since at least October 2020 that uses spear‑phishing Dropbox links, DLL side‑loading and USB‑based propagation to deploy Cobalt Strike beacons and post‑exploitation tools (a signed fake Zoom stealer and a Chrome cookie stealer) against targets primarily in Myanmar and the Philippines; the report provides detailed infection chains, TTPs, IOCs (hashes, domains, IPs), victim statistics (~1,400 Philippines, ~100 Myanmar) and links to the HoneyMyte/Mustang Panda group.