UT is a threat group associated with targeted spearphishing operations against organizations in Taiwan. Observed targeting has focused on non-governmental organizations and suspected universities, indicating a selective intrusion model rather than broad opportunistic malware distribution. The group has been linked to delivery and operation of the LucidRook malware family and a companion reconnaissance utility known as LucidNight. UT’s intrusion activity uses spearphishing emails with Traditional Chinese lures and password-protected archives containing decoy documents crafted to appear credible to Taiwanese recipients. The infection chain includes a dropper referred to as LucidPan, which masquerades as a legitimate security product to reduce suspicion. Execution relies on DLL search order hijacking involving a legitimate Windows Deployment Image Servicing and Management-related executable to load a malicious stager component. LucidRook is characterized by a layered Lua-based architecture implemented within a Windows DLL and supported by Rust-compiled libraries. The malware performs host profiling prior to tasking, including collection of system and software information, encrypts the harvested data, and retrieves additional encrypted Lua bytecode for follow-on functionality. UT has also used persistence via startup-folder shortcut placement and has employed anti-analysis measures including obfuscated strings and a non-standard safe mode intended to hinder dynamic analysis. The observed tooling and victimology are consistent with a focused post-compromise collection and reconnaissance operation. Attribution to a specific nation state is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.