UAT-10362 Deploys LucidRook Lua-Based Malware Against Taiwanese NGOs and Universities
UAT-10362 Deploys LucidRook Lua-Based Malware Against (TL-2026-0345), also tracked as LucidRook Campaign, is a high-severity malware campaign, first published 2026-04-09. It is attributed to UAT-10362 (China) with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-0345
- Threat ID
- TL-2026-0345
- Also known as
- LucidRook Campaign, Lucid Toolkit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-09
- Last reviewed
- 2026-04-09
- Attribution
- UAT-10362
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, ngo, education, civil-society, academia
- Target regions
- Taiwan, East Asia
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in UAT-10362 Deploys LucidRook Lua-Based Malware Against
Malware and tooling: LucidKnight, LucidPawn, LucidRook, FTP-based C2 with compromised Taiwanese printing company servers
China-nexus threat actor UAT-10362 conducts spear-phishing campaigns against Taiwanese NGOs and universities using LucidRook, a novel Lua 5.4.8-based stager embedded in a 64-bit DLL with Rust-compiled libraries. The tiered toolkit includes LucidPawn (geofenced dropper targeting zh-TW locales) and LucidKnight (Gmail-based recon exfiltrator), leveraging DLL side-loading via masqueraded DISM binaries and compromised FTP servers for C2.
How UAT-10362 Deploys LucidRook Lua-Based Malware Against works
UAT-10362 is a previously undocumented China-nexus threat cluster first observed in October 2025 conducting targeted spear-phishing campaigns against Taiwanese non-governmental organizations (NGOs) and suspected universities. The actor deploys a sophisticated tiered malware toolkit consisting of LucidRook, LucidPawn, and LucidKnight, designed for targeted intelligence collection against civil society and academic institutions in Taiwan.
LucidRook is the primary stager: a 64-bit Windows DLL (~1.6MB, 3,800+ functions) that embeds a full Lua 5.4.8 interpreter alongside Rust-compiled libraries. It masquerades as a COM DLL via a DllGetClassObject export and downloads staged Lua bytecode payloads from compromised FTP servers. The stager implements a safe mode that disables package.loadlib and omits the debug library to harden against analysis. String obfuscation uses a two-stage scheme: per-string arithmetic address calculation followed by XOR decryption with a seed|mask key reconstruction. Host reconnaissance collects user accounts, computer names, driver information, installed applications, and running processes, encrypting results with an embedded RSA public key and packaging into password-protected ZIP archives (archive4.zip) uploaded to FTP C2.
LucidPawn serves as the initial dropper, sharing LucidRook''s COM DLL masquerade technique and obfuscation scheme. It performs geofencing via GetUserDefaultUILanguage(), checking for Traditional Chinese (0x0404/zh-TW) with a 0xF7FF mask that also accepts zh-HK (0x0C04), ensuring execution only on Taiwanese or Hong Kong systems. LucidPawn sends a DNS beacon to an Out-of-band Application Security Testing (OAST) service at d.2fcc7078.digimg.store to verify network connectivity, then decrypts AES-encrypted embedded binaries, establishes persistence via Startup folder LNK files, and launches LucidRook via DLL side-loading.
LucidKnight is a companion 64-bit Windows DLL reconnaissance tool with embedded Rust components. It collects computer name, OS version, processor architecture, CPU usage, running processes, and installed software, writing to four TXT files encrypted with a separate RSA public key. Exfiltration occurs via Gmail SMTP using the lettre Rust crate: the sender account fexopuboriw972@gmail.com transmits encrypted archive.zip to the temporary address crimsonanabel@powerscrews.com with a Traditional Chinese subject line.
Two distinct infection chains deliver the malware. The LNK-based vector uses password-protected RAR archives containing LNK files with substituted PDF icons and hidden directories nested four levels deep. The LNK targets the Pester framework Build.bat (a LOLBAS technique) to execute PowerShell, which launches the legitimate DISM binary index.exe. DLL search order hijacking loads the malicious DismCore.dll (LucidPawn), which decrypts embedded binaries to %APPDATA%\Local\Microsoft\Windows\Apps, renames the legitimate DISM executable to msedge.exe for persistence, and opens decoy documents. The EXE-based vector distributes 7-Zip archives containing Cleanup.exe, a .NET dropper masquerading as a Trend Micro product with a falsified compilation timestamp (2065-01-12). It Base64-decodes embedded files, drops the DISM executable and LucidRook stager to C:\ProgramData, creates a Startup LNK for persistence, and displays a fake cleanup completed message.
C2 infrastructure leverages two compromised FTP servers (1.34.253.131 and 59.124.71.242) belonging to Taiwanese printing companies whose FTP credentials were publicly exposed on their corporate websites. FTP operations use binary/passive mode with plaintext authentication. The actor generates different passwords and payloads per target using the shared C2 infrastructure, with payload archives protected by unique passwords and RSA encryption. The OAST service at dnslog.ink provides DNS beaconing without dedicated infrastructure.
MITRE ATT&CK techniques used in TL-2026-0345
collection
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol
persistence
T1547 Boot or Logon Autostart Execution; T1574 Hijack Execution Flow
initial-access
resource-development
Affected products and versions in UAT-10362 Deploys LucidRook Lua-Based Malware Against
- Microsoft — Windows
Vulnerable versions: 10 (64-bit); 11 (64-bit); Server 2016; Server 2019; Server 2022 - Microsoft — DISM (Deployment Image Servicing and Management)
Vulnerable versions: All versions (legitimate binary abused for DLL side-loading)
Remediation for UAT-10362 Deploys LucidRook Lua-Based Malware Against
Immediate actions
- Block FTP C2 IPs 1.34.253.131 and 59.124.71.242 at network perimeter
- Block DNS resolution for d.2fcc7078.digimg.store and dnslog.ink
- Block email communication with fexopuboriw972@gmail.com and crimsonanabel@powerscrews.com
- Hunt for DismCore.dll in non-standard locations (%APPDATA%\Local\Microsoft\Windows\Apps, C:\ProgramData)
- Search for msedge.exe binaries that are actually renamed DISM executables
- Check Startup folders for suspicious LNK files launching msedge.exe or index.exe
- Scan endpoints for SHA256 IOCs associated with LucidRook, LucidPawn, and LucidKnight
Workarounds
- Restrict PowerShell execution policies to prevent Build.bat LOLBAS exploitation
- Remove or rename Pester Build.bat from PowerShell module paths
- Block .LNK file execution from archive extraction paths
- Disable FTP protocol at network boundaries where not business-required
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading via DISM binaries
- Implement application whitelisting to prevent unauthorized DLL loading
- Monitor FTP traffic for anomalous connections to Taiwanese IP ranges
- Configure email security gateways to detect Gmail-based exfiltration patterns
- Implement LOLBAS detection rules for Pester Build.bat abuse
- Deploy Lua interpreter execution monitoring on endpoints
- Establish geofencing-aware threat hunting for zh-TW targeted campaigns
Timeline of UAT-10362 Deploys LucidRook Lua-Based Malware Against
- Cisco Talos observes first spear-phishing attack delivering LucidRook targeting a Taiwanese NGO
- LNK-based infection chain identified using Pester Build.bat LOLBAS technique with DISM DLL side-loading
- EXE-based infection chain discovered using Cleanup.exe masquerading as Trend Micro product in 7-Zip archives
- LucidKnight companion reconnaissance tool identified with Gmail SMTP exfiltration capability
- Campaign expanded to suspected Taiwanese universities alongside NGO targets
- Two compromised FTP servers (1.34.253.131, 59.124.71.242) at Taiwanese printing companies identified as C2 infrastructure
- Full analysis of tiered toolkit (LucidRook/LucidPawn/LucidKnight) with Lua 5.4.8 interpreter and Rust components completed
- Cisco Talos publishes detailed technical analysis and IOCs for LucidRook campaign
- Widespread media coverage from The Hacker News, CybersecurityNews, GBHackers, and CyberPress
- As of 2026-05-29, this remains active: Cisco Talos disclosed UAT-10362's LucidRook toolkit on 2026-04-08 against Taiwanese NGOs/universities, an ongoing China-nexus espionage campaign with no reported takedown, arrest, or sinkhole. No CVE/patch applies (DLL side-loading tradecraft), the actor is undisrupted, and compromised-FTP/OAST C2 is trivially rotatable.
Sources cited for UAT-10362 Deploys LucidRook Lua-Based Malware Against
- Cisco Talos: New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations
- Cisco Talos IOCs: LucidRook indicators
- The Hacker News: UAT-10362 Targets Taiwanese NGOs with LucidRook Malware
- CybersecurityNews: Hackers Use Fake Security Software to Deliver LucidRook
- GBHackers: LucidRook in Taiwan Cyberattacks
- BackBox News: LucidRook observed in targeted attacks against Taiwanese organizations
- Malware.news: LucidRook Lua-based malware analysis
- CyberPress: Fake Security Tools Used To Spread LucidRook
Threats related to UAT-10362 Deploys LucidRook Lua-Based Malware Against
Detection coverage for TL-2026-0345
As of 2026-04-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0345 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.