logo

LucidRook: Sophisticated Spear-Phishing Campaign Targets Taiwan with Custom Malware Stack

ID: 61b1e747-502a-54d7-8844-19dd2bcbe2a4

STIX ID: report--61b1e747-502a-54d7-8844-19dd2bcbe2a4

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

Cisco Talos uncovered a sophisticated, targeted campaign (UAT-10362) against Taiwanese NGOs and universities using a multi-component malware suite: LucidRook (Lua-interpreter stager with Rust libraries), LucidKnight (recon/exfiltration via Gmail), and LucidPawn (Traditional Chinese environment-locked dropper). Attackers employ malicious LNK/EXE lures disguised as antivirus, abuse public infrastructure and compromised FTP servers for C2, and implement layered anti-analysis and region-specific checks to maintain stealth and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.