UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
ID: 2bcf6225-81f3-5ec9-a8da-286036d3c4ed
STIX ID: report--2bcf6225-81f3-5ec9-a8da-286036d3c4ed
Feed Name: The Hacker News
Cisco Talos describes a targeted spear-phishing campaign (UAT-10362) observed in October 2025 that delivers a new Lua-based stager named LucidRook via a dropper called LucidPawn using DLL side‑loading. The report details two infection chains (LNK mimicking a PDF and an EXE posing as Trend Micro), the inclusion of an embedded Lua 5.4.8 interpreter and Rust libraries in the DLL, geofencing to Traditional Chinese (zh-TW), use of OAST services and compromised FTP for C2, and an ancillary reconnaissance/exfiltration component (LucidKnight) suggesting a tiered, stealth-focused toolkit aimed at Taiwanese NGOs and suspected universities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
