MUSTANG_PANDA__2021__Kaspersky-LuminousMothAPT-Sweeping-attackspdf_07-14-2021.pdf
ID: 9d52af03-7f73-4eef-9b45-10897356e166
STIX ID: report--9d52af03-7f73-4eef-9b45-10897356e166
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2021-09-07
Last Modified Date: 2021-09-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report profiles the LuminousMoth APT — a sophisticated, Chinese‑language affiliated campaign active since at least October 2020 that uses spear‑phishing Dropbox links, DLL side‑loading and USB‑based propagation to deploy Cobalt Strike beacons and post‑exploitation tools (a signed fake Zoom stealer and a Chrome cookie stealer) against targets primarily in Myanmar and the Philippines; the report provides detailed infection chains, TTPs, IOCs (hashes, domains, IPs), victim statistics (~1,400 Philippines, ~100 Myanmar) and links to the HoneyMyte/Mustang Panda group.
