UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
Spear-phishing tactics that target Taiwanese non-governmental organizations (NGOs) and suspected universities have been linked to an undiscovered threat cluster known as UAT-10362, which is responsible for the deployment of a new Lua-based malware known as LucidRook.
According to Cisco Talos researcher Ashley Shen, LucidRook is an advanced stager that downloads and runs staged Lua bytecode payloads by embedding a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL).
The assault uses RAR or 7-Zip archive lures to deliver a dropper named LucidPawn, which opens a decoy file and runs LucidRook, according to the cybersecurity organization, which said it noticed the activity in October 2025. The incursion set's usage of DLL side-loading to run LucidPawn and Luci...

