LucidRook: Sophisticated Spear-Phishing Campaign Targets Taiwan with Custom Malware Stack
ID: 61b1e747-502a-54d7-8844-19dd2bcbe2a4
STIX ID: report--61b1e747-502a-54d7-8844-19dd2bcbe2a4
Feed Name: securityonline.info
Cisco Talos uncovered a sophisticated, targeted campaign (UAT-10362) against Taiwanese NGOs and universities using a multi-component malware suite: LucidRook (Lua-interpreter stager with Rust libraries), LucidKnight (recon/exfiltration via Gmail), and LucidPawn (Traditional Chinese environment-locked dropper). Attackers employ malicious LNK/EXE lures disguised as antivirus, abuse public infrastructure and compromised FTP servers for C2, and implement layered anti-analysis and region-specific checks to maintain stealth and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
