SYMBOLCOMMON_NAMEaka. SYNONYMS
win.lucidpawn (Back to overview)

LucidPawn

VTCollection    

According to Cisco Talos, LucidPawn is a dropper for LucidRook and LucidKnight. It uses region-specific anti-analysis checks and executes only in Traditional Chinese language environments associated with Taiwan.

References
2026-04-07 ⋅ Talos Intelligence ⋅ Ashley Shen
New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
LucidKnight LucidPawn LucidRook UAT-10362
Yara Rules
[TLP:WHITE] win_lucidpawn_auto (20260917 | Detects win.lucidpawn.)
rule win_lucidpawn_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.lucidpawn."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lucidpawn"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 00c9 0fb6c9 84c0 0f45ca }
            // n = 4, score = 100
            //   00c9                 | inc                 al
            //   0fb6c9               | mov                 byte ptr [esp + 0x90], al
            //   84c0                 | dec                 esp
            //   0f45ca               | mov                 dword ptr [esp + 0x98], ecx

        $sequence_1 = { 00c0 89c7 eb64 488b4e20 }
            // n = 4, score = 100
            //   00c0                 | add                 al, al
            //   89c7                 | mov                 edi, eax
            //   eb64                 | jmp                 0x66
            //   488b4e20             | dec                 eax

        $sequence_2 = { 01c2 488b3e 488b5e08 4189d7 }
            // n = 4, score = 100
            //   01c2                 | dec                 ebp
            //   488b3e               | mov                 esi, esp
            //   488b5e08             | dec                 eax
            //   4189d7               | lea                 ebp, [0xec3c7]

        $sequence_3 = { 01c0 428944b414 4d89e6 488d2dc7c30e00 }
            // n = 4, score = 100
            //   01c0                 | dec                 eax
            //   428944b414           | shl                 edx, cl
            //   4d89e6               | add                 dword ptr [esp + 0x3c], edx
            //   488d2dc7c30e00       | inc                 eax

        $sequence_4 = { 00c0 fec0 88842490000000 4c898c2498000000 }
            // n = 4, score = 100
            //   00c0                 | add                 al, al
            //   fec0                 | mov                 edi, eax
            //   88842490000000       | jmp                 0x66
            //   4c898c2498000000     | dec                 eax

        $sequence_5 = { 01c1 49ffc7 89cf ebb6 }
            // n = 4, score = 100
            //   01c1                 | add                 dword ptr [esp + 0x40], edx
            //   49ffc7               | inc                 eax
            //   89cf                 | mov                 bh, 0xf
            //   ebb6                 | dec                 eax

        $sequence_6 = { 01542440 40b70f e9???????? 48c7c2ffffffff }
            // n = 4, score = 100
            //   01542440             | add                 esi, esi
            //   40b70f               | add                 dword ptr [esp + 0x3c], edx
            //   e9????????           |                     
            //   48c7c2ffffffff       | inc                 eax

        $sequence_7 = { 0154243c 40b716 e9???????? 48c7c2ffffffff }
            // n = 4, score = 100
            //   0154243c             | add                 cl, cl
            //   40b716               | movzx               ecx, cl
            //   e9????????           |                     
            //   48c7c2ffffffff       | test                al, al

    condition:
        7 of them and filesize < 2131968
}
Download all Yara Rules