LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in Targeted Espionage Against Taiwanese Civil Society

LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in (TL-2026-0334), also tracked as Lucid Toolkit, is a high-severity malware campaign, first published 2026-04-08. It is attributed to UAT-10362 (China) with medium confidence, affects Multiple Windows Endpoints, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-0334

Threat ID
TL-2026-0334
Also known as
Lucid Toolkit, LucidRook Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-04-08
Last reviewed
2026-04-08
Attribution
UAT-10362
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
ngo, education, civil-society, research, academia
Target regions
Taiwan, East Asia
Detection rules
9
Indicators of compromise
26

Malware and tooling in LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

Malware and tooling: LucidKnight, LucidPawn, LucidRook

Cisco Talos uncovered a new threat cluster tracked as UAT-10362 conducting spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and universities. The campaigns deliver a novel three-component Lua-based malware toolkit — LucidPawn (dropper), LucidRook (Lua bytecode stager), and LucidKnight (Gmail-based reconnaissance tool) — representing new TTPs from a suspected China-nexus threat actor targeting Taiwan's civil society.

How LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in works

Cisco Talos researchers identified a previously undocumented threat activity cluster designated UAT-10362 conducting targeted spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and academic institutions. The campaigns deliver a novel malware toolkit collectively referred to as the Lucid family, consisting of three distinct components operating in a coordinated attack chain.

The initial infection vector is spear-phishing emails containing malicious attachments tailored to Taiwanese civil society targets. Upon execution, the LucidPawn dropper component establishes initial foothold on the victim system and deploys the primary payload. LucidRook, the core component of the toolkit, is a Lua bytecode stager that leverages the lightweight Lua scripting engine (MITRE ATT&CK T1059.011) to execute obfuscated bytecode payloads. By using compiled Lua bytecode rather than plaintext scripts, the malware evades static analysis and signature-based detection tools that lack Lua bytecode parsing capabilities.

The third component, LucidKnight, is a reconnaissance and data collection tool that abuses Gmail as a command-and-control channel. By tunneling C2 communications through legitimate Gmail infrastructure, the malware blends with normal email traffic and bypasses network security controls that would flag connections to suspicious domains. The toolkit also uses the domain digimg.store for DNS-based interaction callbacks, a technique commonly observed in post-exploitation frameworks for verifying command execution on target systems.

The two command-and-control IP addresses identified (1.34.253.131 and 59.124.71.242) both resolve to Chunghwa Telecom (HINET) address space in Taiwan, suggesting the threat actor either compromised legitimate Taiwanese infrastructure for use as relay nodes or deliberately selected Taiwanese hosting to blend with expected network traffic patterns from the target organizations.

UAT-10362 is assessed with moderate confidence to be a China-nexus threat actor based on victimology (Taiwanese NGOs and universities aligned with civil society and democracy advocacy), operational patterns consistent with Chinese cyber espionage campaigns, and infrastructure choices. The targeting of Taiwan's civil society sector is consistent with long-standing Chinese intelligence collection priorities, particularly monitoring organizations involved in cross-strait relations, democracy promotion, and academic research on sensitive geopolitical topics.

The use of Lua as the primary execution engine represents an evolution in tradecraft for China-nexus actors, who have historically favored compiled languages or common scripting engines. Lua's lightweight footprint, embeddability, and relative obscurity in enterprise security monitoring make it an attractive choice for evading endpoint detection and response (EDR) solutions that may not have robust Lua bytecode analysis capabilities.

MITRE ATT&CK techniques used in TL-2026-0334

collection

T1005 Data from Local System

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

persistence

T1547 Boot or Logon Autostart Execution

initial-access

T1566 Phishing

Affected products and versions in LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

  • Multiple — Windows Endpoints
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016+

Remediation for LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

Immediate actions

  • Block IOC IP addresses 1.34.253.131 and 59.124.71.242 at network perimeter
  • Block domain digimg.store and all subdomains at DNS resolver and proxy
  • Block email addresses fexopuboriw972@gmail.com and crimsonanabel@powerscrews.com
  • Search email gateways for spear-phishing messages targeting NGO and university staff
  • Scan endpoints for SHA256 hashes listed in IOC feed using EDR or YARA rules
  • Monitor for anomalous Lua interpreter or LuaJIT process execution

Workarounds

  • Restrict Lua runtime execution via application control policies
  • Block outbound DNS to non-corporate resolvers to detect DNS tunneling
  • Enable enhanced email filtering for attachments from unknown senders targeting civil society organizations

Longer-term hardening

  • Deploy EDR with behavioral detection for Lua bytecode execution and scripting engine abuse
  • Implement application whitelisting to prevent unauthorized Lua runtime execution
  • Enable DNS logging and monitor for DNS-based interaction callback services (digimg.store, interact.sh, dnslog.cn)
  • Monitor Gmail API and SMTP traffic for anomalous automated access patterns from endpoints
  • Conduct targeted security awareness training for NGO and university staff on spear-phishing threats
  • Implement email authentication (SPF, DKIM, DMARC) to reduce spear-phishing effectiveness
  • Deploy network segmentation to limit lateral movement from compromised endpoints

Timeline of LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

  • Earliest estimated campaign activity by UAT-10362 targeting Taiwanese NGOs based on infrastructure registration and first observed samples
  • Spear-phishing campaigns delivering LucidPawn dropper observed targeting Taiwanese universities and NGOs
  • LucidRook Lua bytecode stager deployed on compromised systems following successful LucidPawn execution
  • LucidKnight reconnaissance tool observed using Gmail as C2 channel for data collection from compromised organizations
  • DNS callback activity to digimg.store subdomains detected from compromised endpoints, confirming active C2 communication
  • Cisco Talos begins investigation and attribution analysis of UAT-10362 campaign and Lucid malware toolkit
  • Cisco-Talos IOCs repository updated with SHA256 hashes, IP addresses, domain, and email indicators for LucidRook campaign
  • Cisco Talos publishes research report and IOCs for LucidRook malware and UAT-10362 threat cluster
  • As of 2026-05-29, this remains an ACTIVE espionage threat: UAT-10362 (China-nexus) and its custom Lua LucidRook/LucidPawn/LucidKnight toolkit were only disclosed by Cisco Talos on 2026-04-08, with no arrests, takedown, or successor. Its resilient OAST/compromised-FTP infrastructure is trivially replaceable, and EDR-evading Lua tradecraft keeps the actor an undisrupted, ongoing risk to Taiwanese civil society.

Sources cited for LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

Threats related to LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in

Detection coverage for TL-2026-0334

As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0334 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats