Cisco Talos uncovered LucidRook, a Lua-based modular backdoor used in targeted spear-phishing attacks on Taiwanese NGOs and universities. The UAT-10362 group employed dual infection chains and stealthy payload updates. #LucidRook #Taiwan
Hashtag
#LucidRook
Advertisement · 728 × 90
0
0
0
0
UAT-10362 targets Taiwanese NGOs and suspected universities using spear-phishing to deliver LucidPawn dropper and LucidRook malware. The attack leverages DLL side-loading and encrypted Lua bytecode for stealthy data exfiltration. #Taiwan #LucidRook
0
0
0
0
~Talos~
UAT-10362 targets Taiwanese NGOs with new Lua-based LucidRook malware via spear-phishing and abused FTP servers.
-
IOCs: 1. 34. 253[. ]131, 59. 124. 71[. ]242, D. 2fcc7078. digimg[. ]store
-
#LucidRook #Malware #ThreatIntel
0
0
0
0