Also known as: academic institutions, tracked as, Asylum Ambuscade
UAT-10362 was first identified by Cisco Talos through a cluster of spear‑phishing attacks against Taiwanese civil society organizations and higher education institutions in October 2025. Victims received a password‑protected 7‑ZIP archive from an email that appeared to originate from an authorized mail server, hinting at potential compromise or spoofing of legitimate infrastructure. The payload chain began with an LNK shortcut file containing a disguised document icon; opening it triggered the execution of a native DLL stager named LucidRook. 64‑bit, Lua‑compiled, LucidRook embeds a Lua 5.4 interpreter and loads additional Lua bytecode from its command‑and‑control (C2) server via FTP. The C2 domain pattern is “D.2fcc7078.digimg.store”, which forwards to the public Out‑of‑Band Application Security Testing service dnslog.inK, allowing the adversary to confirm successful exploitation without maintaining dedicated infrastructure. LucidRook’s design demonstrates a modular approach: the same loader can deliver different Lua payloads per target, and developers can update behavior rapidly. The malware includes obfuscation layers and anti‑analysis features that hinder static and dynamic analysis, while its use of legitimate sending domains shows an emphasis on stealth and operational security. A related component discovered during analysis is LucidPawn, a lightweight dropper used for reconnaissance or as a precursor to LucidRook. Together these tools illustrate the actor’s flexible toolkit strategy, deploying only the required payloads for each engagement.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-10362 is a sophisticated threat actor that conducts targeted spear‑phishing campaigns against Taiwanese NGOs and universities. They deliver the custom LucidRook DLL stager, which embeds a Lua interpreter to execute modular payloads from an attacker-controlled C2. The group’s use of legitimate mail infrastructure and public OAST services underscores its mature operational tradecraft.
Goals & Targeting
The actor’s primary motive appears to be financial gain, yet they selectively target entities that may hold valuable data or have weak security postures, such as NGOs, universities, and public sector organizations in Taiwan. Their targeting profile extends across multiple sectors—education, government, healthcare, critical infrastructure—and includes a diverse geographic reach from China to Europe, suggesting opportunistic exploitation of perceived vulnerabilities rather than narrowly defined espionage objectives. Victims are typically mid‑tier institutions or non‑profit entities that may not enforce strict email filtering, making spear‑phishing an attractive vector.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns by UAT-10362 focus on a narrow geographic area—primarily Taiwan—using LNK and EXE infection chains delivered as password‑protected ZIP files. The actor employs a moderately high operational tempo, with activity observed in late October 2025 and uploads to public malware repositories by December 2025. Victim profiles are consistent: NGOs, universities, and other organizations that likely lack advanced email security. Each operation appears meticulously engineered to avoid detection, leveraging modularity for rapid re‑tooling and public services like dnslog.inK to stealthily verify exploitation success.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on public reports from Cisco Talos and Seclookup research, which provide detailed technical analysis of LucidRook deployment. Confidence in the actor’s Taiwan focus and use of spear‑phishing with LNK/ZIP attachments is high due to repeated observations. However, details about global scope, persistence mechanisms beyond boot‑autostart, or credential‑stealing tactics remain limited, creating moderate uncertainty regarding full strategic objectives beyond financial gain.
No campaigns linked yet.
No observed data linked yet.
18
Techniques
47
Tools
0
Campaigns
39
IOCs
0
Observed Data
9
Tactics