LucidRook Malware Targets NGOs and Universities in Taiwan

LucidRook Malware Targets NGOs and Universities in Taiwan

First seen 9 Apr 2026, 12:31 UTC Blog.TalosintelligenceGbhackersCybersecuritynewsBleepingcomputerSecurityaffairs.Co+1 84% similarity 61.2

Article Content

Browse articles
ThreatCluster

A new Lua-based malware named LucidRook is being deployed in targeted attacks against non-governmental organizations and universities in Taiwan. The threat group UAT-10362 is believed to be behind these spear-phishing campaigns, which began in October 2025. Attackers utilize phishing emails containing password-protected archives and fake security tools to deliver the malware. LucidRook features a modular design with a built-in Lua execution environment, allowing for stealthy updates and execution of second-stage payloads. The malware collects system information and exfiltrates data using FTP and Gmail GMTP. Cisco Talos researchers have identified two infection chains involving a malware dropper called LucidPawn and a fake antivirus executable. The attacks are characterized by high levels of planning and technical sophistication, complicating reverse-engineering efforts. Current assessments indicate that the attacks are part of a targeted intrusion campaign.

Key Points: • LucidRook malware targets NGOs and universities in Taiwan through spear-phishing. • The malware employs a modular design with a Lua execution environment for stealth. • Attackers use fake security tools and phishing emails to deliver the malware.

ThreatCluster AI How this analysis works

Timeline

2025-10-01
LucidRook observed in targeted attacks on Taiwanese organizations.
2026-04-09
Cisco Talos publishes findings on LucidRook malware.

Community

Browse all →