Hackers Use Fake Security Software to Deliver LucidRook Malware in Taiwan Attacks
ID: 6e0daaf6-a17a-5a1e-b366-3fd259dc65c2
STIX ID: report--6e0daaf6-a17a-5a1e-b366-3fd259dc65c2
Feed Name: cybersecurityNews.com
*Cisco Talos uncovered a targeted campaign against Taiwanese NGOs and universities delivering a new Lua/Rust-based malware family called LucidRook via spearphishing and password-protected archives disguised as Trend Micro software; the attack chain uses an LNK-triggered DLL sideload (DismCore.dll), persistence via a Startup LNK, encrypted collection of host data, and exfiltration to compromised FTP servers, with a companion reconnaissance tool named LucidNight and published IoCs and Snort rules for detection.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
