Security Experts:

Connect with us

Hi, what are you looking for?



LuminosityLink RAT Author Sentenced to 30 Months in Prison

The maker of the LuminosityLink remote access Trojan (RAT) was sentenced to 30 months in federal prison, the United States Department of Justice announced this week.

The maker of the LuminosityLink remote access Trojan (RAT) was sentenced to 30 months in federal prison, the United States Department of Justice announced this week.

The man, Colton Grubbs, 21, of Stanford, Kentucky, admitted in court earlier this year to designing, marketing, and selling LuminosityLink, a piece of malware that could record keystrokes, access the camera and microphone for surveillance purposes, download files, and steal login credentials.

As part of his guilty plea, Grubbs also revealed that he was aware of the fact that some of his customers would use the software to remotely access and control computers without their owner’s knowledge or consent.

The RAT was being sold via the luminosity[.]link and luminosityvpn[.]com websites, but the malware author suspended sales via luminosity[.]link in July 2017, half a year before law enforcement agencies released the details of an operation specifically targeting LuminosityLink users.

Grubbs, who admitted to selling the malicious program for $39.99 apiece to more than 6,000 customers, also provided assistance on the use of the RAT for unauthorized computer intrusions. The Trojan was used to target victims throughout the United States and around the world.

Under federal law, Grubbs must serve 85% of his prison sentence. He will be released under supervision of the United States Probation Office for a term of three years.

Grubbs has also been ordered to forfeit the proceeds of his crimes, including 114 Bitcoin (valued at over $725,000 at the moment), which was seized by the Federal Bureau of Investigation.

“Our modern society is dependent on computers, mobile devices, and the use of the internet. It is essential that we vigorously prosecute those who erode that confidence and illicitly gain access to computer systems and the electronic information of others. Everyone benefits when this deceitful conduct is discovered, investigated, and prosecuted,” Robert M. Duncan, Jr., United States Attorney for the Eastern District of Kentucky, said.

Related: Malware Creator Admits to Building and Selling LuminosityLink RAT

Related: Hackers Linked to Luminosity RAT Targeted by Law Enforcement

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Expert Insights

Related Content


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.


The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Malware & Threats

Microsoft plans to improve the protection of Office users by blocking XLL add-ins from the internet.


Artificial intelligence is competing in another endeavor once limited to humans — creating propaganda and disinformation.


Video games developer Riot Games says source code was stolen from its development environment in a ransomware attack


A digital ad fraud scheme dubbed "VastFlux" spoofed over 1,700 apps and peaked at 12 billion ad requests per day before being shut down.


A new study by McAfee and the Center for Strategic and International Studies (CSIS) named a staggering figure as the true annual cost of...


Cybercriminals earned significantly less from ransomware attacks in 2022 compared to 2021 as victims are increasingly refusing to pay ransom demands.