UAT-10362 linked to LucidRook attacks targeting Taiwan-based institutions
ID: 8c1eb662-f69b-5894-a59c-c3d15675f62f
STIX ID: report--8c1eb662-f69b-5894-a59c-c3d15675f62f
Feed Name: Security Affairs
**Executive summary:** The report describes LucidRook, a modular Lua-based Windows DLL stager delivered via targeted spear-phishing (password-protected archives and shortened URLs) against Taiwanese NGOs and universities and linked to the UAT-10362 actor. Researchers observed two infection chains (shortcut/LOLBAS-based and .NET EXE dropper), DISM DLL sideloading, persistence via Startup LNKs, FTP-based C2 that retrieves encrypted Lua bytecode, and companion tooling (LucidPawn, LucidKnight) used for reconnaissance and exfiltration; the activity is assessed as a targeted, technically sophisticated intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
