As cited
Copy frozen at (site build).
threat intel
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Cisco Talos identified UAT-10147, a Chinese-speaking threat actor operating a sophisticated multi-platform intrusion toolkit targeting IIS and Linux servers for SEO fraud monetization and persistent access. The actor's SPECTRE backdoor features cross-platform command-and-control, process injection, credential theft, and Bring Your Own Virtual Driver (BYOVD) based EDR bypass via vulnerable kernel drivers. The Specter Linux rootkit component demonstrates AI-assisted code generation in its development, providing kernel-level persistence through ftrace-based syscall hooking and signal-based inter-process communication that survives reboots and user-level security controls.
Why it matters: Organizations operating internet-facing IIS and Linux servers are at immediate risk of compromise by this operationally mature actor; defenders should hunt for BYOVD driver abuse (CVE-2019-16098, CVE-2021-21551), ASHX web handlers, BadIIS malware, and registry modifications from named-pipe impersonation attacks, and consider blocking the actor's known vulnerable drivers at the kernel level.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers.
Why it matters: Organizations running internet-facing IIS and Linux servers are at immediate risk of compromise by UAT-10147, which can disable EDR protections entirely, exfiltrate credentials, and establish persistent kernel-level access that survives reboots and typical security controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers.
Why it matters: Organizations running internet-facing IIS and Linux servers are at immediate risk of compromise by UAT-10147, which can disable EDR protections entirely, exfiltrate credentials, and establish persistent kernel-level access that survives reboots and typical security controls.
- Source published
- First seen by Cybersecurity Tracker