logo

Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks

ID: 1e412fd8-a3d8-5518-9546-bb81c2c55b5b

STIX ID: report--1e412fd8-a3d8-5518-9546-bb81c2c55b5b

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Cisco Talos reports a targeted, espionage-focused campaign (UAT-10362) using spear-phishing and fake security tools to deploy a modular malware suite — notably LucidRook (Lua/Rust-based stager), LucidPawn (dropper), and LucidKnight (reconnaissance) — against Taiwanese NGOs and academic-related targets; the actors employ living-off-the-land techniques, DLL sideloading, encrypted staged payloads delivered via FTP, geo/language checks to avoid analysis, and tailored decoys to maintain stealth and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.