- DismCore.dllMalicious DLL used for sideloading LucidRook via renamed Microsoft Edge executable
- LucidRookLua-based modular malware used in targeted attacks on NGOs and universities in Taiwan
- LucidPawnMalware dropper delivered via LNK-based infection chain; decrypts and deploys legitimate executable with malicious DLL
- LucidKnightReconnaissance tool related to LucidRook; abuses Gmail SMTP for data exfiltration
ThreatNoir Morning Brief — April 10
Morning Review in IT Security — April 10, 2026
The threat landscape continues to evolve with sophisticated campaigns targeting critical sectors worldwide. Today's briefing covers emerging malware threats against NGOs and universities, advanced phishing operations targeting corporate leadership, state-sponsored attacks on critical infrastructure, and a significant ransomware incident affecting healthcare services.
New 'LucidRook' Malware Used in Targeted Attacks on NGOs, Universities
A newly identified Lua-based malware called LucidRook has emerged as part of coordinated spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. The malware family includes multiple variants including DismCore.dll, LucidKnight, and LucidPawn, each designed to establish persistent access within targeted organizations. Source: New 'LucidRook' malware used in targeted attacks on NGOs, universities
The use of Lua as the underlying programming language represents an attempt by threat actors to evade traditional detection mechanisms that focus on more common malware development frameworks. Organizations in the education and nonprofit sectors should implement enhanced email filtering and conduct security awareness training focused on identifying sophisticated spear-phishing attempts.
New VENOM Phishing Attacks Steal Senior Executives' Microsoft Logins
A previously undocumented phishing-as-a-service platform designated VENOM is actively targeting credential theft from C-suite executives across multiple industries. The threat actors operating this service employ device-code phishing techniques that attempt to bypass multi-factor authentication protections. Source: New VENOM phishing attacks steal senior executives' Microsoft logins
The targeting of senior leadership positions represents a high-value attack vector, as compromised executive accounts provide threat actors with elevated privileges and access to sensitive corporate systems and data. Organizations should prioritize implementing conditional access policies and hardware security keys for executive accounts to mitigate the effectiveness of credential-based attacks.
Iranian Attacks on US Critical Infrastructure Puts 3,900 Devices in Crosshairs
Researchers at Censys have identified approximately 3,900 exposed devices that are currently vulnerable to Iranian government-sponsored cyber operations targeting critical infrastructure sectors including energy, water systems, and US government facilities. The attacks leverage MITRE ATT&CK techniques T0801 (Activate Firmware Update Mode) and T0849 (Modify Controller Tasking) to compromise industrial control systems. Source: Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs
The exposure of thousands of industrial operational technology devices underscores the ongoing vulnerability of critical infrastructure to state-sponsored threat actors. Organizations operating in affected sectors must prioritize vulnerability patching, network segmentation, and implementation of robust monitoring for anomalous controller behavior.
Healthcare IT Solutions Provider ChipSoft Hit by Ransomware Attack
Dutch healthcare software vendor ChipSoft experienced a significant ransomware attack that resulted in the forced offline status of its website and digital services serving both patients and healthcare providers. The incident demonstrates the cascading impact that attacks on healthcare IT infrastructure can have across entire care delivery networks. Source: Healthcare IT solutions provider ChipSoft hit by ransomware attack
The disruption to healthcare services highlights the critical importance of business continuity planning and rapid incident response capabilities within the healthcare technology sector. Healthcare organizations dependent on third-party software providers should maintain updated contingency plans and communication protocols for service disruptions.
The convergence of these threats across NGO, corporate, government, and healthcare sectors demonstrates the breadth of current cyber threats. Organizations across all industries should maintain heightened vigilance regarding phishing attempts, ensure timely patching of critical systems, and develop comprehensive incident response capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- VENOMPhishing-as-a-service platform targeting C-suite Microsoft credentials
- device-code phishingTactic used within VENOM to trick victims into approving rogue device access
- PLC exploitation for industrial automation control manipulation
- Potential device firmware compromise in OT environments