Gradual adoption of AI-assisted development workflows | Image: Cisco Talos
At a glance
| Factor | Details |
|---|---|
| Actor or Group | UAT-10147 (Suspected Chinese-speaking group) |
| Activity Type | SEO fraud monetization, credential theft, and process injection via malware deployment |
| Targets or Victims | Internet-facing IIS and Linux servers |
| Scale | Unknown number of global victims |
| Status | Currently active and monitored by cybersecurity researchers |
| Source | Cisco Talos |
TL;DR
The suspected Chinese-speaking cybercrime group UAT-10147 deploys the SPECTRE cross-platform implant to compromise global IIS and Linux servers. This newly discovered backdoor utilizes advanced endpoint detection and response (EDR) bypass techniques. These techniques include Bring Your Own Vulnerable Driver (BYOVD) tactics and Linux rootkits. Researchers suggest the threat actors are also adopting artificial intelligence to accelerate their offensive malware development.
What Happened
Security analysts recently uncovered a highly capable threat group operating a multi-platform post-exploitation ecosystem. According to the investigation, the actor uses custom malware, open-source offensive utilities, and advanced in-memory web shell deployment techniques. Central to this campaign is a newly identified backdoor. As noted by analysts, “The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.”
The Windows variant of this malware distinguishes itself by prioritizing obfuscation. It relies on a dual-layered defense strategy featuring runtime API resolution and a per-string pseudorandom number generator scheme. This allows the SPECTRE cross-platform implant to bypass static detection methods. Furthermore, the backdoor executes a weighted anti-analysis scoring routine. It checks for sandbox environments, physical memory limits, and sleep acceleration. If the system appears to be an analysis environment, the malware self-terminates.
To disable security software on Windows, the malware downloads vulnerable drivers from its command server. Attackers use these drivers to perform targeted kernel writes, neutralizing popular EDR agents. On Linux systems, the threat actors deploy a rootkit named Specter. This rootkit uses the native instrumentation framework of the Linux kernel to redirect execution, hiding processes and network connections.
Who is Behind It
Researchers assess with high confidence that UAT-10147 is a Chinese-speaking intrusion actor. Artifacts recovered from the tools indicate the developers use Chinese terminology. These artifacts include references to specific customized parameters. Additionally, analysts discovered derogatory Chinese strings within the payload configurations.
Interestingly, evidence suggests the group uses automated code generation. Investigators noted that “Cisco Talos’ analysis of recovered source code suggests portions of the Linux rootkit development may have incorporated AI-assisted code generation workflows, highlighting the growing role of generative AI in accelerating offensive malware development.” The rigid structure and educational tone found in the rootkit source code strongly indicate machine generation.
Impact or Scale
The exact financial scale of the campaign remains undisclosed, but the impact is widespread. The group systematically targets internet-facing IIS and Linux servers. They turn compromised systems into hosts for search engine optimization fraud. The campaign utilizes an advanced web handler that silently takes over an application request pipeline. This mechanism serves fabricated content to search engine crawlers. It successfully poisons web rankings while delivering malicious payloads to unsuspecting visitors.
The UAT-10147 SPECTRE cross-platform implant also uses named pipe impersonation to escalate privileges. Once it acquires SYSTEM privileges, it dumps the SAM, SYSTEM, and SECURITY registry hives. It also incorporates functions to extract Google Chrome and Microsoft Edge login data. The malware places these files in temporary directories for offline decryption. On Linux servers, the backdoor establishes persistence by installing a fraudulent system service. This ensures the rootkit loads before any security tooling starts.
What Comes Next or How Readers Can Stay Protected
As UAT-10147 continues to refine its arsenal, organizations must implement strong defense strategies. Security teams should proactively monitor their networks for the unauthorized deployment of known vulnerable drivers. Ensuring that Windows servers utilize virtualization-based security can help mitigate Bring Your Own Vulnerable Driver attacks.
Administrators should also audit Linux endpoints for unexpected kernel modules. They must pay particular attention to modules disguised as standard power management components.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!