New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

2026-04-10T07:23:40Zbe43ba1a79ec8d01cc32428e3bed845cc2554b77be2fd4aa7cd0d73618e7be53
adobe-readerbackdoorchipsoftcisacredential-theftgoogle-chrome-dbscinfostealerivanti-epmmjoomlalualucidrookmagentomalwarephaasphishingransomwaresession-cookie-theftsmart-sliderspear-phishingsupply-chain-compromisesvg-skimmervenomweb-skimmingwordpresszero-day

What happened

A batch of BleepingComputer reports highlights widespread, active threats and incidents: a new Lua-based malware dubbed LucidRook used in targeted spear-phishing against NGOs and universities in Taiwan; VENOM, a phishing-as-a-service platform targeting C-suite Microsoft credentials; Smart Slider 3 Pro update system hijacked to push backdoored WordPress/Joomla plugins; ongoing exploitation of an Adobe Acrobat/Reader zero-day since December; a critical Ivanti Endpoint Manager Mobile (EPMM) flaw that CISA ordered federal agencies to patch; a ransomware outage at Dutch healthcare vendor ChipSoft;$

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
be43ba1a79ec8d01cc32428e3bed845cc2554b77be2fd4aa7cd0d73618e7be53
Enrichment time
2026-04-10T07:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.