Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2866 articles · 109455 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

New Lua-based malware 'LucidRook' observed in targeted attacks against Taiwanese organizations

60% confidence

Description

Cisco Talos identified a sophisticated malware family called LucidRook, delivered via spear-phishing campaigns targeting Taiwanese NGOs and universities. LucidRook acts as a stager embedding a Lua interpreter and Rust-compiled libraries within a DLL to execute staged Lua bytecode payloads. The dropper 'LucidPawn' employs region-specific anti-analysis checks and executes only in Traditional Chinese language environments. Two infection chains were observed, involving malicious LNK/EXE files disguised as antivirus software, leveraging compromised FTP servers and OAST services for C2 infrastructure.

Related News (1 articles)

Tier C
Cisco Talos1d ago
New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedApr 8, 2026
Last enriched5h ago
Tags
spear-phishingmalwaretaiwan
Trending Score34
Source articles1
Independent1
Info Completeness3/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Apr 8, 2026
Actively Exploited
Apr 9, 2026
Exploit Available
Apr 9, 2026
Discovered by ZDM
Apr 9, 2026