LucidPawn is a malware dropper associated with the UAT-10362 threat cluster and observed in spear-phishing campaigns discovered in October 2025 targeting Taiwanese non-governmental organizations and universities. It was delivered in password-protected RAR or 7-Zip archives, including infection chains using malicious LNK shortcut files disguised as PDFs and archives themed as legitimate security software. In the LNK-based chain, opening the shortcut triggered PowerShell/LOLBAS execution from nested hidden folders, leading to LucidPawn execution via DLL side-loading. LucidPawn then opened a decoy document and launched the LucidRook malware stager, again using DLL side-loading through legitimate DISM-related binaries. Reported LucidPawn behavior includes decrypting embedded payloads, dropping a legitimate DISM executable and the LucidRook stager, writing files to %APPDATA%\Local\Microsoft\WindowsApps, renaming the DISM executable to msedge.exe, deleting the original lure LNK, and establishing persistence with a Startup-folder LNK file. Cisco Talos reported that LucidPawn shares Rust code, obfuscation methods, and COM DLL masquerading traits with LucidRook. It also performs region-specific anti-analysis and geo-targeting by checking the Windows UI language and only continuing execution in Traditional Chinese environments associated with Taiwan or Hong Kong (zh-TW/zh-HK), helping restrict execution to intended victims. LucidPawn was also observed querying public OAST infrastructure, including dnslog[.]ink via D.2fcc7078.digimg[.]store, likely to confirm execution or connectivity. At least one variant installed LucidKnight instead of the standard payload set. Reported indicators tied to LucidPawn variants and related delivery include SHA-256 d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964, dnslog[.]ink, and D.2fcc7078.digimg[.]store.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attacks, discovered in October 2025, utilize RAR or 7-Zip archives with lures to deliver a dropper called LucidPawn. This dropper then opens a decoy file and launches LucidRook, employing DLL side-loading for execution.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
one uses a Windows Shortcut (LNK) file disguised as a PDF, which executes a PowerShell script to sideload LucidPawn.
The malware also hides strings using multi-stage XOR and address calculation tricks. Payloads are protected with different passwords and keys per campaign for modular deployment
The archives contained fake government or security-related decoy documents to distract victims.
It uses LOLBAS techniques and PowerShell to run code through trusted Windows tools, reducing detection.
It uses geo-targeting, checking Windows UI language and only runs on Traditional Chinese systems (Taiwan/HK), avoiding sandboxes.
LucidPawn implements a geo-targeting anti-analysis execution gate by querying the host’s Windows UI language via the GetUserDefaultUILanguage() API. Execution continues only when the system UI language matches Traditional Chinese environments associated with Taiwan.
It uses geo-targeting, checking Windows UI language and only runs on Traditional Chinese systems (Taiwan/HK), avoiding sandboxes.
In both cases, the actor abused an Out-of-band Application Security Testing (OAST) service and compromised FTP servers for command-and-control (C2) infrastructure.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A dropper used in the infection chain to open a decoy document and launch LucidRook via DLL side-loading.
A dropper linked to LucidRook that uses LOLBAS techniques and PowerShell, decrypts and drops payloads including a legitimate DISM executable and the LucidRook stager, abuses DLL sideloading for execution, establishes persistence via Startup LNKs, performs geo-targeting for Traditional Chinese systems, and may query a DNS OAST service to confirm infection.
A dropper delivered via archive lures that opens a decoy file and launches LucidRook using DLL side-loading. It also implements geofencing by checking for Traditional Chinese Taiwan language settings (zh-TW) before continuing execution.
Malware dropper used in the LNK-based infection chain. It decrypts and deploys a legitimate executable renamed to mimic Microsoft Edge along with a malicious DLL for sideloading LucidRook.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.