Blog.Talosintelligence
LucidRook Malware Targets NGOs and Universities in Taiwan
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new Lua-based malware named LucidRook is being deployed in targeted attacks against non-governmental organizations and universities in Taiwan. The threat group UAT-10362 is believed to be behind these spear-phishing campaigns, which began in October 2025. Attackers utilize phishing emails containing password-protected archives and fake security tools to deliver the malware. LucidRook features a modular design with a built-in Lua execution environment, allowing for stealthy updates and execution of second-stage payloads. The malware collects system information and exfiltrates data using FTP and Gmail GMTP. Cisco Talos researchers have identified two infection chains involving a malware dropper called LucidPawn and a fake antivirus executable. The attacks are characterized by high levels of planning and technical sophistication, complicating reverse-engineering efforts. Current assessments indicate that the attacks are part of a targeted intrusion campaign.
Key Points: • LucidRook malware targets NGOs and universities in Taiwan through spear-phishing. • The malware employs a modular design with a Lua execution environment for stealth. • Attackers use fake security tools and phishing emails to deliver the malware.