New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations

2026-04-08T20:51:52Zcfa56ace9bc4d5f458cf9848c0cfef48730bce8ca7bb475c2060803c1f66457b
AxiosCanvaEDR evasionHikVisionLuaLucidRookNEXUS ListenerNPM supply chainQilinSaaS notification abuseTP-LinkTaiwanUAT-10362UAT-10608credential harvestingmsimg32.dllransomwarespear-phishingsupply chainthreat intelligencevulnerability disclosure

What happened

Cisco Talos published a series of investigations and analysis highlighting active targeted campaigns and broader trending threats. The most notable item describes a new Lua-based malware family dubbed “LucidRook” delivered via spear-phishing by a cluster tracked as UAT-10362 against Taiwanese NGOs and suspected universities. Other coverage includes: a large-scale automated credential-harvesting operation using a framework called NEXUS Listener (UAT-10608); an Axios NPM supply-chain incident and broader supply-chain advisories; abuse of SaaS notification pipelines to deliver phishing/spam; QILN

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
cfa56ace9bc4d5f458cf9848c0cfef48730bce8ca7bb475c2060803c1f66457b
Enrichment time
2026-04-08T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.