logo

UAT-10362 linked to LucidRook attacks targeting Taiwan-based institutions

ID: 8c1eb662-f69b-5894-a59c-c3d15675f62f

STIX ID: report--8c1eb662-f69b-5894-a59c-c3d15675f62f

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Executive summary:** The report describes LucidRook, a modular Lua-based Windows DLL stager delivered via targeted spear-phishing (password-protected archives and shortened URLs) against Taiwanese NGOs and universities and linked to the UAT-10362 actor. Researchers observed two infection chains (shortcut/LOLBAS-based and .NET EXE dropper), DISM DLL sideloading, persistence via Startup LNKs, FTP-based C2 that retrieves encrypted Lua bytecode, and companion tooling (LucidPawn, LucidKnight) used for reconnaissance and exfiltration; the activity is assessed as a targeted, technically sophisticated intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.