Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-10362

Also known as: academic institutions, tracked as, Asylum Ambuscade

Description

UAT-10362 was first identified by Cisco Talos through a cluster of spear‑phishing attacks against Taiwanese civil society organizations and higher education institutions in October 2025. Victims received a password‑protected 7‑ZIP archive from an email that appeared to originate from an authorized mail server, hinting at potential compromise or spoofing of legitimate infrastructure. The payload chain began with an LNK shortcut file containing a disguised document icon; opening it triggered the execution of a native DLL stager named LucidRook. 64‑bit, Lua‑compiled, LucidRook embeds a Lua 5.4 interpreter and loads additional Lua bytecode from its command‑and‑control (C2) server via FTP. The C2 domain pattern is “D.2fcc7078.digimg.store”, which forwards to the public Out‑of‑Band Application Security Testing service dnslog.inK, allowing the adversary to confirm successful exploitation without maintaining dedicated infrastructure. LucidRook’s design demonstrates a modular approach: the same loader can deliver different Lua payloads per target, and developers can update behavior rapidly. The malware includes obfuscation layers and anti‑analysis features that hinder static and dynamic analysis, while its use of legitimate sending domains shows an emphasis on stealth and operational security. A related component discovered during analysis is LucidPawn, a lightweight dropper used for reconnaissance or as a precursor to LucidRook. Together these tools illustrate the actor’s flexible toolkit strategy, deploying only the required payloads for each engagement.

Goals & Targeting

Targeted Sectors

Non profit
Government
Financial services
Education
Defense
Telecommunications
Manufacturing
Healthcare
Media
Mining
Critical infrastructure
Utilities

Targeted Countries / Regions

TW
UA
CN
BR
US
PL
JP
MX
KZ
VN
TR
IR
DE
AZ
NL

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

UAT-10362 is a sophisticated threat actor that conducts targeted spear‑phishing campaigns against Taiwanese NGOs and universities. They deliver the custom LucidRook DLL stager, which embeds a Lua interpreter to execute modular payloads from an attacker-controlled C2. The group’s use of legitimate mail infrastructure and public OAST services underscores its mature operational tradecraft.

Goals & Targeting

The actor’s primary motive appears to be financial gain, yet they selectively target entities that may hold valuable data or have weak security postures, such as NGOs, universities, and public sector organizations in Taiwan. Their targeting profile extends across multiple sectors—education, government, healthcare, critical infrastructure—and includes a diverse geographic reach from China to Europe, suggesting opportunistic exploitation of perceived vulnerabilities rather than narrowly defined espionage objectives. Victims are typically mid‑tier institutions or non‑profit entities that may not enforce strict email filtering, making spear‑phishing an attractive vector.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious attachments
  • Use of legitimate or compromised mail infrastructure
  • Deployment of custom DLL stagers embedding a Lua interpreter
  • Modular payload delivery via FTP and public OAST domains
  • Obfuscation and anti‑analysis techniques
  • Staged execution with password‑protected archives
  • Dynamic configuration via externally retrieved Lua bytecode
  • Stealthy use of public services to confirm C2 connectivity

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Exfiltration
Defense Evasion

ATT&CK Techniques

T1566.001
T1071
T1547
T1190
T1555
T1036
T1523
T1027
T1041
T1059.001
T1258
T1204
T1476

Software / Tooling

LucidRook
LucidPawn
LucidKnight
LNK-based Infection Tool (Unspecified)
Lua-based Stager
FTP C2 Client

Campaigns & Victims

Campaigns by UAT-10362 focus on a narrow geographic area—primarily Taiwan—using LNK and EXE infection chains delivered as password‑protected ZIP files. The actor employs a moderately high operational tempo, with activity observed in late October 2025 and uploads to public malware repositories by December 2025. Victim profiles are consistent: NGOs, universities, and other organizations that likely lack advanced email security. Each operation appears meticulously engineered to avoid detection, leveraging modularity for rapid re‑tooling and public services like dnslog.inK to stealthily verify exploitation success.

IOC Patterns

  • Spear‑phishing attachment with password‑protected .7z archive
  • Archive containing a malicious LNK shortcut referencing a disguised document icon
  • DLL stager executing Lua bytecode retrieved over FTP
  • C2 domain redirecting to dnslog.inK
  • Outbound DNS queries to *.digimg.store
  • Use of legitimate corporate SMTP servers for delivery
  • Embedded Lua interpreter within 64‑bit DLL

Recommended Actions

  • Implement attachment filtering rules that block .lnk files in email attachments, especially within ZIP archives
  • Deploy file integrity monitoring on endpoints to detect execution of unexpected 64‑bit DLLs named “LucidRook” or similar
  • Block outbound FTP connections to unfamiliar domains and monitor for queries to *.digimg.store
  • Configure DNS inspection to alert on queries to dnslog.inK or other common OAST services
  • Enforce proper email authentication (SPF, DKIM, DMARC) to reduce spoofed legitimate sender scenarios
  • Educate users about malicious attachments and the risks of opening LNK shortcuts embedded in documents

Suggested Tags

APT
Phishing
Malware
Lua-based Stager
DLL Loader
Spear‑phishing Attachment
Financial Motivation
Targeted Intrusion
Education Sector
NGO

Confidence Assessment

The assessment is based primarily on public reports from Cisco Talos and Seclookup research, which provide detailed technical analysis of LucidRook deployment. Confidence in the actor’s Taiwan focus and use of spear‑phishing with LNK/ZIP attachments is high due to repeated observations. However, details about global scope, persistence mechanisms beyond boot‑autostart, or credential‑stealing tactics remain limited, creating moderate uncertainty regarding full strategic objectives beyond financial gain.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cti.cyberdudebivash.in — Cited by web research for: T1566
  2. blog.talosintelligence.com — Cited by web research for: Payload
  3. attack.mitre.org — Cited by web research for: Interception
  4. blog.talosintelligence.com — Cited by web research for: Unknown
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. https://www.bleepingcomputer.com/news/security/new-lucidrook-malware-used-in-targeted-attacks-on-ngos-universities/ — Cited by AI analysis.
  7. https://blog.seclookup.com/unmasking-lucidrook-a-deep-dive-into-uat-10362-s-lua-based-campaign-against-taiwan — Cited by AI analysis.
  8. https://www.wokb.cz/ALERT/alerts_cam — Cited by AI analysis.

Intel Summary

18

Techniques

47

Tools

0

Campaigns

39

IOCs

0

Observed Data

9

Tactics

Tags

Phishing
APT
Espionage
Malware
Spear phishing
Information stealing
Educational Sector
Taiwan
Lua-based Stager
DLL Loader
Spear‑phishing Attachment
Financial Motivation
Targeted Intrusion
Education Sector
NGO

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Taiwan (TW)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.