LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in Targeted Espionage Against Taiwanese Civil Society
LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in (TL-2026-0334), also tracked as Lucid Toolkit, is a high-severity malware campaign, first published 2026-04-08. It is attributed to UAT-10362 (China) with medium confidence, affects Multiple Windows Endpoints, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-0334
- Threat ID
- TL-2026-0334
- Also known as
- Lucid Toolkit, LucidRook Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-08
- Last reviewed
- 2026-04-08
- Attribution
- UAT-10362
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- ngo, education, civil-society, research, academia
- Target regions
- Taiwan, East Asia
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
Malware and tooling: LucidKnight, LucidPawn, LucidRook
Cisco Talos uncovered a new threat cluster tracked as UAT-10362 conducting spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and universities. The campaigns deliver a novel three-component Lua-based malware toolkit — LucidPawn (dropper), LucidRook (Lua bytecode stager), and LucidKnight (Gmail-based reconnaissance tool) — representing new TTPs from a suspected China-nexus threat actor targeting Taiwan's civil society.
How LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in works
Cisco Talos researchers identified a previously undocumented threat activity cluster designated UAT-10362 conducting targeted spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and academic institutions. The campaigns deliver a novel malware toolkit collectively referred to as the Lucid family, consisting of three distinct components operating in a coordinated attack chain.
The initial infection vector is spear-phishing emails containing malicious attachments tailored to Taiwanese civil society targets. Upon execution, the LucidPawn dropper component establishes initial foothold on the victim system and deploys the primary payload. LucidRook, the core component of the toolkit, is a Lua bytecode stager that leverages the lightweight Lua scripting engine (MITRE ATT&CK T1059.011) to execute obfuscated bytecode payloads. By using compiled Lua bytecode rather than plaintext scripts, the malware evades static analysis and signature-based detection tools that lack Lua bytecode parsing capabilities.
The third component, LucidKnight, is a reconnaissance and data collection tool that abuses Gmail as a command-and-control channel. By tunneling C2 communications through legitimate Gmail infrastructure, the malware blends with normal email traffic and bypasses network security controls that would flag connections to suspicious domains. The toolkit also uses the domain digimg.store for DNS-based interaction callbacks, a technique commonly observed in post-exploitation frameworks for verifying command execution on target systems.
The two command-and-control IP addresses identified (1.34.253.131 and 59.124.71.242) both resolve to Chunghwa Telecom (HINET) address space in Taiwan, suggesting the threat actor either compromised legitimate Taiwanese infrastructure for use as relay nodes or deliberately selected Taiwanese hosting to blend with expected network traffic patterns from the target organizations.
UAT-10362 is assessed with moderate confidence to be a China-nexus threat actor based on victimology (Taiwanese NGOs and universities aligned with civil society and democracy advocacy), operational patterns consistent with Chinese cyber espionage campaigns, and infrastructure choices. The targeting of Taiwan's civil society sector is consistent with long-standing Chinese intelligence collection priorities, particularly monitoring organizations involved in cross-strait relations, democracy promotion, and academic research on sensitive geopolitical topics.
The use of Lua as the primary execution engine represents an evolution in tradecraft for China-nexus actors, who have historically favored compiled languages or common scripting engines. Lua's lightweight footprint, embeddability, and relative obscurity in enterprise security monitoring make it an attractive choice for evading endpoint detection and response (EDR) solutions that may not have robust Lua bytecode analysis capabilities.
MITRE ATT&CK techniques used in TL-2026-0334
collection
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
persistence
T1547 Boot or Logon Autostart Execution
initial-access
Affected products and versions in LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
- Multiple — Windows Endpoints
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016+
Remediation for LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
Immediate actions
- Block IOC IP addresses 1.34.253.131 and 59.124.71.242 at network perimeter
- Block domain digimg.store and all subdomains at DNS resolver and proxy
- Block email addresses fexopuboriw972@gmail.com and crimsonanabel@powerscrews.com
- Search email gateways for spear-phishing messages targeting NGO and university staff
- Scan endpoints for SHA256 hashes listed in IOC feed using EDR or YARA rules
- Monitor for anomalous Lua interpreter or LuaJIT process execution
Workarounds
- Restrict Lua runtime execution via application control policies
- Block outbound DNS to non-corporate resolvers to detect DNS tunneling
- Enable enhanced email filtering for attachments from unknown senders targeting civil society organizations
Longer-term hardening
- Deploy EDR with behavioral detection for Lua bytecode execution and scripting engine abuse
- Implement application whitelisting to prevent unauthorized Lua runtime execution
- Enable DNS logging and monitor for DNS-based interaction callback services (digimg.store, interact.sh, dnslog.cn)
- Monitor Gmail API and SMTP traffic for anomalous automated access patterns from endpoints
- Conduct targeted security awareness training for NGO and university staff on spear-phishing threats
- Implement email authentication (SPF, DKIM, DMARC) to reduce spear-phishing effectiveness
- Deploy network segmentation to limit lateral movement from compromised endpoints
Timeline of LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
- Earliest estimated campaign activity by UAT-10362 targeting Taiwanese NGOs based on infrastructure registration and first observed samples
- Spear-phishing campaigns delivering LucidPawn dropper observed targeting Taiwanese universities and NGOs
- LucidRook Lua bytecode stager deployed on compromised systems following successful LucidPawn execution
- LucidKnight reconnaissance tool observed using Gmail as C2 channel for data collection from compromised organizations
- DNS callback activity to digimg.store subdomains detected from compromised endpoints, confirming active C2 communication
- Cisco Talos begins investigation and attribution analysis of UAT-10362 campaign and Lucid malware toolkit
- Cisco-Talos IOCs repository updated with SHA256 hashes, IP addresses, domain, and email indicators for LucidRook campaign
- Cisco Talos publishes research report and IOCs for LucidRook malware and UAT-10362 threat cluster
- As of 2026-05-29, this remains an ACTIVE espionage threat: UAT-10362 (China-nexus) and its custom Lua LucidRook/LucidPawn/LucidKnight toolkit were only disclosed by Cisco Talos on 2026-04-08, with no arrests, takedown, or successor. Its resilient OAST/compromised-FTP infrastructure is trivially replaceable, and EDR-evading Lua tradecraft keeps the actor an undisrupted, ongoing risk to Taiwanese civil society.
Sources cited for LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
- Cisco Talos: New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations
- Cisco-Talos IOCs: LucidRook indicators of compromise
- MITRE ATT&CK T1059.011: Command and Scripting Interpreter - Lua
- Picus Security: T1059.011 Lua in MITRE ATT&CK Explained
- AlienVault OTX: digimg.store threat intelligence
- Proofpoint: China-Aligned Espionage Actors Target Taiwan
- Darktrace: digimg.store observed in Ivanti EPMM exploitation campaigns
Threats related to LucidRook Lua-Based Malware Toolkit Used by UAT-10362 in
Detection coverage for TL-2026-0334
As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0334 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.