Thehackernews
UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
UAT-10147, a Chinese-speaking threat actor, has been identified using the SPECTRE backdoor and a Linux rootkit to conduct sophisticated multi-platform attacks. The group employs advanced techniques such as Bring Your Own Vulnerable Driver (BYOVD) to disable endpoint detection and response (EDR) protections. Cisco Talos has analyzed the malware, revealing AI-assisted code generation and specific command structures for evasion. Organizations with internet-facing IIS and Linux servers are particularly at risk, especially if they utilize known vulnerable drivers like RTCore64.sys. Immediate isolation of compromised systems is advised to prevent lateral movement. Forensic analysis should focus on kernel integrity and unauthorized service installations. The threat actor's toolkit also includes SEO fraud tools, indicating a broader scope of impact beyond just data theft.
Key Points: • UAT-10147 uses SPECTRE backdoor and Linux rootkit for cross-platform attacks. • Advanced techniques like BYOVD are employed to bypass EDR protections. • Organizations should isolate compromised servers and conduct thorough forensic analysis.