← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
Cisco Talos observed a spear-phishing attack delivering LucidRook, a newly identified stager that targeted a Taiwanese NGO in October 2025. The metadata in the email suggests that it was delivered via authorized mail infrastructure, which implies potential misuse of legitimate sending capabilities.
The email contained a shortened URL that leads to the download of a password protected and encrypted RAR archive. The decryption password was included in the email body. Based on this email and the collected samples, Talos observed two distinct infection chains originating from the delivered archives.
Indicators of Compromise (31)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 08e44f25c764212f33b1d05900a14978 | MD5 of adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143 | 2026-04-15 | |
| FileHash-MD5 | 263d2f844fec137f085cece4d6ae45e5 | MD5 of f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839 | 2026-04-15 | |
| FileHash-MD5 | 2b27f9936aebde7f4797fca3f0500eef | MD5 of c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc | 2026-04-15 | |
| FileHash-MD5 | 7a9d42393f803b5b9b90eac05ad6a65a | MD5 of d49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a | 2026-04-15 | |
| FileHash-MD5 | 8422c64dcafc83841e8a0ebd93564874 | MD5 of b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d | 2026-04-15 | |
| FileHash-MD5 | d4eacad2b7c0a659713216ae62f77b50 | MD5 of bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d | 2026-04-15 | |
| FileHash-MD5 | ed7a850c9b87054da2c1173797bb5bd7 | MD5 of edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809 | 2026-04-15 | |
| FileHash-MD5 | edae483fb8698a3f30b680a02c92525b | MD5 of d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964 | 2026-04-15 | |
| FileHash-SHA1 | 0e16c23f7d44bb70d0f47e7386323cb0ce3400f4 | SHA1 of d49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a | 2026-04-15 | |
| FileHash-SHA1 | 1d4e3b32c7e71e7f71f1afb654b7e990462e4849 | SHA1 of bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d | 2026-04-15 | |
| FileHash-SHA1 | 4f19a836b020159e71e263cd5bcefc6ee5e9f868 | SHA1 of b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d | 2026-04-15 | |
| FileHash-SHA1 | 7248e5992138a3bcea882c1fe8d5e498c2392150 | SHA1 of adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143 | 2026-04-15 | |
| FileHash-SHA1 | 72abfdee582c1c12f2ea97402af1a3e271ce4972 | SHA1 of edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809 | 2026-04-15 | |
| FileHash-SHA1 | 982539c2253d8e25d7242f1d0f3f2d89b985326d | SHA1 of d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964 | 2026-04-15 | |
| FileHash-SHA1 | a4271c542dabea3c9e51e81ee49b87409d340143 | SHA1 of c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc | 2026-04-15 | |
| FileHash-SHA1 | d88b571b886e3b285593fb1259d6bac6c056e565 | SHA1 of f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839 | 2026-04-15 | |
| FileHash-SHA256 | 0305e89110744077d8db8618827351a03bce5b11ef5815a72c64eea009304a34 | — | 2026-04-15 | |
| FileHash-SHA256 | 11ae897d79548b6b44da75f7ab335a0585f47886ce22b371f6d340968dbed9ae | — | 2026-04-15 | |
| FileHash-SHA256 | 166791aac8b056af8029ab6bdeec5a2626ca3f3961fdf0337d24451cfccfc05d | — | 2026-04-15 | |
| FileHash-SHA256 | 6aba7b5a9b4f7ad4203f26f3fb539911369aeef502d43af23aa3646d91280ad9 | — | 2026-04-15 | |
| FileHash-SHA256 | aa7a3e8b59b5495f6eebc19f0654b93bb01fd2fa2932458179a8ae85fb4b8ec1 | — | 2026-04-15 | |
| FileHash-SHA256 | adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143 | — | 2026-04-15 | |
| FileHash-SHA256 | b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d | — | 2026-04-15 | |
| FileHash-SHA256 | bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d | — | 2026-04-15 | |
| FileHash-SHA256 | c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc | — | 2026-04-15 | |
| FileHash-SHA256 | d49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a | — | 2026-04-15 | |
| FileHash-SHA256 | d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964 | — | 2026-04-15 | |
| FileHash-SHA256 | edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809 | — | 2026-04-15 | |
| FileHash-SHA256 | f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839 | — | 2026-04-15 | |
| FileHash-SHA256 | fd11f419e4ac992e89cca48369e7d774b7b2e0d28d0b6a34f7ee0bc1d943c056 | — | 2026-04-15 | |
| hostname | d.2fcc7078.digimg.store | — | 2026-04-15 |