logo

New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

ID: 72de4cb9-17df-51b4-809b-d1bb3cf0fb65

STIX ID: report--72de4cb9-17df-51b4-809b-d1bb3cf0fb65

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Cisco Talos analysis describes LucidRook, a heavily obfuscated Lua-based modular malware used in targeted spear-phishing attacks in Taiwan. Attackers used password-protected archives delivering either an LNK shortcut leading to a dropper (LucidPawn) that sideloads a malicious DLL, or a fake Trend Micro antivirus EXE; the malware hosts an embedded Lua interpreter to fetch and execute second-stage bytecode, enabling flexible, low-forensic-footprint updates. Observed behavior includes system reconnaissance and encrypted exfiltration (FTP and Gmail abuse reported for related tooling), and researchers attribute activity to a capable group tracked as UAT-10362, although the exact post-infection Lua payload was not captured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.