Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks
ID: 1e412fd8-a3d8-5518-9546-bb81c2c55b5b
STIX ID: report--1e412fd8-a3d8-5518-9546-bb81c2c55b5b
Feed Name: GBHackers
Cisco Talos reports a targeted, espionage-focused campaign (UAT-10362) using spear-phishing and fake security tools to deploy a modular malware suite — notably LucidRook (Lua/Rust-based stager), LucidPawn (dropper), and LucidKnight (reconnaissance) — against Taiwanese NGOs and academic-related targets; the actors employ living-off-the-land techniques, DLL sideloading, encrypted staged payloads delivered via FTP, geo/language checks to avoid analysis, and tailored decoys to maintain stealth and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
