LucidKnight is a related 64-bit Windows DLL reconnaissance tool observed in Cisco Talos reporting on UAT-10362 activity targeting Taiwanese NGOs and suspected universities in October 2025. It appears to be part of a broader toolkit associated with the LucidRook/LucidPawn intrusion set and is likely used for reconnaissance prior to LucidRook deployment. Talos observed a LucidPawn variant that installs LucidKnight instead of the standard payload set.
LucidKnight gathers host and system information, including items such as computer name, OS version, processor architecture, CPU usage, running processes, installed software, and other system data. The collected data is encrypted with an embedded RSA public key, packaged into a ZIP archive, and exfiltrated via Gmail SMTP. Reported exfiltration details include use of smtp.gmail.com, ZIP attachments disguised as "Sports Information Platform" or with the Traditional Chinese subject "運動資訊平台," and delivery to a temporary or attacker-controlled email address. One reported sample used the Gmail account fexopuboriw972@gmail.com to send data to crimsonanabel@powerscrews.com. A reported ZIP password was xZh>1<{Km1YD3[V>x]X>=1u(Da)Y=N>u.
LucidKnight shares Rust-compiled components and a similar string-obfuscation scheme with LucidPawn and LucidRook, supporting the assessment that it belongs to the same malware family or operator toolkit. High-confidence associated context links it to threat cluster UAT-10362 and targeted spear-phishing operations against organizations in Taiwan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A related DLL, LucidKnight, has also been observed, capable of exfiltrating system information via Gmail, suggesting a tiered toolkit for reconnaissance before deploying LucidRook.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
On execution, it first collects system data like usernames, processes, and installed software, then encrypts and exfiltrates it.
The data is encrypted using RSA, stored in password-protected archives, and exfiltrated to attacker-controlled infrastructure via FTP. One notable characteristic of LucidKnight is its abuse of Gmail GMTP to exfiltrate collected data...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related DLL used for reconnaissance that exfiltrates system information via Gmail, likely as part of a tiered toolkit preceding LucidRook deployment.
A reconnaissance tool used in the LucidRook intrusion set that gathers system data, encrypts it, and exfiltrates it via Gmail SMTP using ZIP attachments disguised as benign files.
A 64-bit Windows DLL used as a reconnaissance and exfiltration tool that sends system information via Gmail to a temporary email address, likely to profile targets before LucidRook deployment.
Related tool likely used for reconnaissance. It abuses Gmail GMTP to exfiltrate collected data, indicating a flexible toolkit used by the operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.