UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Reported exploitedWindows OSUAT-10147Linux OSOur summary
Cisco Talos has published analysis of a new cross-platform implant named SPECTRE, which is actively being deployed by the threat actor UAT-10147 against Windows and Linux environments. The malware integrates advanced capabilities including process injection, credential theft, and Bring Your Own Vulnerable Driver (BYOVD) techniques to neutralize endpoint detection and response solutions by exploiting known vulnerabilities such as CVE-2019-16098 and CVE-2021-21551.
Notably, the research highlights emerging patterns in offensive security tooling, with indicators suggesting that UAT-10147 utilized AI-assisted workflows to develop parts of the SPECTRE implant and the associated Specter Linux rootkit. This evolution underscores the increasing sophistication of commodity intrusion tooling and its impact on modern enterprise defenses.
Below is the opening; the full story is at Cisco Talos.
From Cisco Talos
Thursday, August 20, 2026 06:00
- UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques.
- The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
- The actor demonstrates operational maturity through the combined use of custom malware, open-source offensive tooling, Bring Your Own Virtual Driver (BYOVD) based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.
- Cisco Talos’ analysis of recovered source code suggests portions of the Linux rootkit development may have incorporated AI-assisted code generation workflows, highlighting the growing role of generative AI in accelerating offensive malware development.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.