UAT-10362 is a previously undocumented threat cluster associated with targeted spear-phishing operations against organizations in Taiwan, particularly non-governmental organizations and universities. The actor has been linked to deployment of the LucidRook malware family and related tooling including LucidPawn and LucidKnight. Available reporting characterizes the group as a capable adversary with mature operational tradecraft and a modular, stealth-focused intrusion toolkit. The actor’s observed initial access method is spear-phishing using password-protected archive lures and decoy documents themed to appear legitimate. Two delivery chains have been documented: one using malicious shortcut files and PowerShell with LOLBAS-style execution, and another using a .NET dropper masquerading as security software. In both cases, the intrusion chain abuses DLL sideloading through legitimate signed binaries to launch payloads while reducing visibility. LucidRook functions as a heavily obfuscated 64-bit Windows DLL stager that embeds a Lua interpreter and Rust-compiled components. It performs host reconnaissance, collects system and environment information, encrypts and exfiltrates collected data, and then retrieves and executes encrypted Lua bytecode as follow-on payloads. The design indicates a flexible post-compromise framework intended for victim-specific tasking while limiting forensic exposure. Observed tradecraft also includes campaign-specific protections, multi-stage string obfuscation, use of public or compromised infrastructure, and geofencing to Traditional Chinese environments associated with intended victims. Related tooling broadens the actor’s capability set. LucidPawn acts as a dropper and execution gate, opening decoy content, enforcing language-based targeting, and establishing persistence through Startup-folder shortcuts. LucidKnight appears to serve as a reconnaissance-focused companion payload that gathers host data and exfiltrates it through email services, suggesting a tiered toolkit in which reconnaissance may precede deployment of the LucidRook stager. The activity is consistent with targeted intrusion operations rather than broad opportunistic malware distribution. No high-confidence public attribution to a nation-state or criminal organization is currently available beyond tracking as UAT-10362.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting spear-phishing campaigns against Taiwanese NGOs and universities to deploy the LucidRook malware via LucidPawn and LucidKnight as part of a stealthy, staged intrusion toolkit.
Conducting targeted spear-phishing intrusions against NGOs and universities in Taiwan using the LucidRook malware cluster and related tooling for stealthy staging, reconnaissance, persistence, and data exfiltration.
Conducting targeted spear-phishing campaigns against Taiwanese NGOs and suspected universities to deploy the LucidRook malware, using archive-based lures, DLL side-loading, staged payload delivery, reconnaissance, and stealth-focused tradecraft.
Conducting targeted spear-phishing intrusion campaigns against non-governmental organizations and universities in Taiwan using the LucidRook malware family and related tooling for reconnaissance, collection, and exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.