SYMBOLCOMMON_NAMEaka. SYNONYMS
win.lucidpawn (Back to overview)

LucidPawn


According to Cisco Talos, LucidPawn is a dropper for LucidRook and LucidKnight. It uses region-specific anti-analysis checks and executes only in Traditional Chinese language environments associated with Taiwan.

References
2026-04-07Talos IntelligenceAshley Shen
New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
LucidKnight LucidPawn LucidRook UAT-10362

There is no Yara-Signature yet.