logo

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

ID: 2bcf6225-81f3-5ec9-a8da-286036d3c4ed

STIX ID: report--2bcf6225-81f3-5ec9-a8da-286036d3c4ed

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos describes a targeted spear-phishing campaign (UAT-10362) observed in October 2025 that delivers a new Lua-based stager named LucidRook via a dropper called LucidPawn using DLL side‑loading. The report details two infection chains (LNK mimicking a PDF and an EXE posing as Trend Micro), the inclusion of an embedded Lua 5.4.8 interpreter and Rust libraries in the DLL, geofencing to Traditional Chinese (zh-TW), use of OAST services and compromised FTP for C2, and an ancillary reconnaissance/exfiltration component (LucidKnight) suggesting a tiered, stealth-focused toolkit aimed at Taiwanese NGOs and suspected universities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.