UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques

UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques

First seen 24 Aug 2026, 09:16 UTC SocprimeThehackernews 77% similarity 73.0

Article Content

Browse articles
ThreatCluster

UAT-10147, a Chinese-speaking threat actor, has been identified using the SPECTRE backdoor and a Linux rootkit to conduct sophisticated multi-platform attacks. The group employs advanced techniques such as Bring Your Own Vulnerable Driver (BYOVD) to disable endpoint detection and response (EDR) protections. Cisco Talos has analyzed the malware, revealing AI-assisted code generation and specific command structures for evasion. Organizations with internet-facing IIS and Linux servers are particularly at risk, especially if they utilize known vulnerable drivers like RTCore64.sys. Immediate isolation of compromised systems is advised to prevent lateral movement. Forensic analysis should focus on kernel integrity and unauthorized service installations. The threat actor's toolkit also includes SEO fraud tools, indicating a broader scope of impact beyond just data theft.

Key Points: • UAT-10147 uses SPECTRE backdoor and Linux rootkit for cross-platform attacks. • Advanced techniques like BYOVD are employed to bypass EDR protections. • Organizations should isolate compromised servers and conduct thorough forensic analysis.

ThreatCluster AI How this analysis works

Timeline

2026-08-21
UAT-10147 toolkit analysis published
Cisco Talos released findings on UAT-10147's use of SPECTRE and AI-assisted malware development.
Socprime
2026-08-24
AI capabilities in UAT-10147 attacks reported
The Hacker News highlighted UAT-10147's use of AI to enhance vulnerability exploitation and server attacks.
Thehackernews

Community

Browse all →

Tracked Entities in This Story