UAT-10147, a Chinese-speaking threat actor, deploys SPECTRE, a cross-platform backdoor targeting IIS and Linux servers. SPECTRE integrates BYOVD-based EDR neutralization via vulnerable drivers, process injection, credential theft, and a Linux kernel rootkit called Specter that uses ftrace for syscall hooking. The actor also employs SEO fraud utilities, Potato family privilege escalation tools, and multiple commodity backdoors. Evidence of AI-assisted development is present in both SPECTRE and Specter source code.
SPECTRE
1 post
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities