LucidRook is a newly identified Lua-based malware family and sophisticated stager associated with the threat cluster UAT-10362. Cisco Talos reported it being used in targeted spear-phishing campaigns discovered in October 2025 against Taiwanese non-governmental organizations and suspected universities. The malware is delivered through password-protected RAR or 7-Zip archives distributed via phishing emails, including lures with shortened URLs and decoy documents in Traditional Chinese. Observed infection chains include a malicious LNK file disguised as a PDF that triggers PowerShell and DLL side-loading via legitimate DISM-related binaries, as well as a .NET executable masquerading as Trend Micro security software that drops and launches the stager. Related tooling observed in the same campaigns includes the LucidPawn dropper and the LucidKnight reconnaissance DLL.
LucidRook is a heavily obfuscated 64-bit Windows DLL that embeds a Lua 5.4.8 interpreter and Rust-compiled libraries. It is designed to download, validate, decrypt, and execute staged Lua bytecode payloads, allowing modular follow-on tasking. Talos reported that it retrieves encrypted payloads over FTP, checks for Lua bytecode magic before execution, and uses anti-analysis measures including extensive string obfuscation and a non-standard Lua safe mode that disables dynamic library loading and omits the debug library. The malware performs host reconnaissance prior to staging, collecting information such as usernames, computer names, installed applications, running processes, drive or driver information, and user profile details. Collected data is encrypted with an embedded RSA public key, stored in files such as 1.bin, 2.bin, and 3.bin, compressed into password-protected ZIP archives, and exfiltrated to external infrastructure.
The campaign infrastructure included compromised or publicly exposed FTP servers and use of an OAST service for execution confirmation. Reported FTP infrastructure included 1.34.253[.]131 and 59.124.71[.]242. Additional reported indicators and artifacts tied to LucidRook activity include dnslog[.]ink, digimg[.]store, archive1.zip, archive4.zip, index.bin, and the sample SHA-256 edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809. Talos assessed with medium confidence that the activity represents a targeted intrusion campaign rather than opportunistic malware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new threat cluster, UAT-10362, has been identified targeting Taiwanese non-governmental organizations and universities with spear-phishing campaigns to deploy a novel Lua-based malware named LucidRook. This sophisticated stager embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute further Lua bytecode payloads.
A newly identified malware called LucidRook has been spotted targeting organizations across Taiwan, hiding inside what appears to be legitimate security software.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Cisco Talos uncovered a cluster of activity we track as UAT-10362 conducting spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and suspected universities to deliver a newly identified malware family, “LucidRook.”
This sophisticated stager embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute further Lua bytecode payloads.
The researchers identified two infection chains, one using an LNK shortcut file that ultimately delivered a malware dropper called LucidPawn, and an EXE-based chain that leveraged a fake antivirus executable impersonating Trend Micro Worry-Free Business Security Services.
LucidRook itself is a heavily obfuscated 64-bit Windows DLL designed for stealth
A 64-bit Windows DLL, LucidRook, is heavily obfuscated to deter analysis and detection.
The second chain involves an executable masquerading as a Trend Micro antivirus program, which acts as a .NET dropper to launch LucidRook.
On execution, it first collects system data like usernames, processes, and installed software, then encrypts and exfiltrates it.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel Lua-based malware delivered as a heavily obfuscated 64-bit Windows DLL. It embeds a Lua interpreter and Rust-compiled libraries, collects system information, exfiltrates it to an external server, and then receives and executes encrypted Lua bytecode payloads.
A sophisticated 64-bit Windows DLL stager that embeds a Lua 5.4.8 interpreter and Rust-compiled libraries, downloads encrypted staged payloads from C2 over FTP, executes Lua bytecode locally, collects system information, encrypts and exfiltrates data, and supports flexible per-target tasking.
A heavily obfuscated 64-bit Windows DLL that collects system information, exfiltrates it to an external server, and then downloads, decrypts, and executes staged Lua bytecode payloads using an embedded Lua 5.4.8 interpreter.
A sophisticated Lua-based stager with a layered design that embeds a Lua interpreter alongside Rust-compiled libraries within a Windows DLL. It gathers host information, stores it in encrypted files, uploads collected data to compromised FTP servers, and retrieves an encrypted Lua bytecode payload from command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.