CYBERSECURITYTRACKER
TRACKING4,379 stories824 vuln stories
Permanent story citation

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4776

As cited

Citation snapshot as of .

threat intel

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos identified UAT-10147, a Chinese-speaking threat actor operating a sophisticated multi-platform intrusion toolkit targeting IIS and Linux servers for SEO fraud monetization and persistent access. The actor's SPECTRE backdoor features cross-platform command-and-control, process injection, credential theft, and Bring Your Own Virtual Driver (BYOVD) based EDR bypass via vulnerable kernel drivers. The Specter Linux rootkit component demonstrates AI-assisted code generation in its development, providing kernel-level persistence through ftrace-based syscall hooking and signal-based inter-process communication that survives reboots and user-level security controls.

Why it matters: Organizations operating internet-facing IIS and Linux servers are at immediate risk of compromise by this operationally mature actor; defenders should hunt for BYOVD driver abuse (CVE-2019-16098, CVE-2021-21551), ASHX web handlers, BadIIS malware, and registry modifications from named-pipe impersonation attacks, and consider blocking the actor's known vulnerable drivers at the kernel level.

Source published
First seen by Cybersecurity Tracker

Source attribution