← Back to BrewedIntel
malwarehighLua-based malwareSpear phishingTargeted attacksLucidRook

Apr 09, 2026 • Bill Toulas

New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

A new Lua-based malware named LucidRook has been identified in active spear-phishing campaigns targeting non-governmental organizations (NGOs) and...

Source
Bleeping Computer
Category
malware
Severity
high

Executive Summary

A new Lua-based malware named LucidRook has been identified in active spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. This malware represents an emerging threat to academic and non-profit sectors in the region. Organizations should immediately enhance email filtering capabilities, conduct security awareness training to recognize phishing attempts, and deploy endpoint detection and response solutions. Given the targeted nature of this campaign, high-value entities in the education and NGO sectors should be especially vigilant and report any suspicious communications to their security teams.

Summary

A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. [...]

Published Analysis

A new Lua-based malware named LucidRook has been identified in active spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. This malware represents an emerging threat to academic and non-profit sectors in the region. Organizations should immediately enhance email filtering capabilities, conduct security awareness training to recognize phishing attempts, and deploy endpoint detection and response solutions. Given the targeted nature of this campaign, high-value entities in the education and NGO sectors should be especially vigilant and report any suspicious communications to their security teams. A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. [...] A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. [...]

Linked Entities

  • LucidRook