CYBERSECURITYTRACKER
TRACKING
Permanent story citation

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4776

As cited

Copy frozen at (site build).

threat intel

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos identified UAT-10147, a Chinese-speaking threat actor operating a sophisticated multi-platform intrusion toolkit targeting IIS and Linux servers for SEO fraud monetization and persistent access. The actor's SPECTRE backdoor features cross-platform command-and-control, process injection, credential theft, and Bring Your Own Virtual Driver (BYOVD) based EDR bypass via vulnerable kernel drivers. The Specter Linux rootkit component demonstrates AI-assisted code generation in its development, providing kernel-level persistence through ftrace-based syscall hooking and signal-based inter-process communication that survives reboots and user-level security controls.

Why it matters: Organizations operating internet-facing IIS and Linux servers are at immediate risk of compromise by this operationally mature actor; defenders should hunt for BYOVD driver abuse (CVE-2019-16098, CVE-2021-21551), ASHX web handlers, BadIIS malware, and registry modifications from named-pipe impersonation attacks, and consider blocking the actor's known vulnerable drivers at the kernel level.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers.

Why it matters: Organizations running internet-facing IIS and Linux servers are at immediate risk of compromise by UAT-10147, which can disable EDR protections entirely, exfiltrate credentials, and establish persistent kernel-level access that survives reboots and typical security controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers.

Why it matters: Organizations running internet-facing IIS and Linux servers are at immediate risk of compromise by UAT-10147, which can disable EDR protections entirely, exfiltrate credentials, and establish persistent kernel-level access that survives reboots and typical security controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary