HomeSecurityUAT-10147: AI-assisted attacks with SPECTRE and Linux Rootkit

UAT-10147: AI-assisted attacks with SPECTRE and Linux Rootkit

The UAT-10147 group is emerging as one of the most sophisticated Chinese-speaking cybercrime groups of our time, leveraging artificial intelligence tools to scale attacks on Windows and Linux web servers worldwide. According to new research from Cisco Talos , the group is developing a cross-platform implant called SPECTRE , which combines EDR bypass , credential theft, and a Linux rootkit into a single package . The range of targets, reaching 170,000 URLs , reveals an industrial-scale operation.

UAT-10147 Chinese-speaking SPECTRE team implant AI attacks servers

UAT-10147's activity came to light after the discovery of an open directory at 139.180.197[.]150, which communicated with compromised machines and hosted tools, implants, and target lists. The group primarily targets the education, media, technology, and gaming, with the highest concentration of victims in Brazil, Bolivia, China, Canada , and Vietnam. However, the target list reveals that the top five target countries are the United States, India, the United Kingdom, Germany and the Netherlands, suggesting much broader ambitions.

The group's primary driver is financial exploitation through SEO fraud and data theft. Cisco Talos assesses with medium to high confidence that this is a Chinese-speaking group, based on linguistic artifacts, usernames, tool overlaps, and infrastructure analysis. What sets UAT-10147 apart from other similar groups is the integration of artificial intelligence tools into every phase of the attack cycle.

See also: Hackers use CyberStrikeAI for AI-powered attacks

UAT-10147: How AI is transforming attacks to industrial scale

UAT-10147’s use of AI isn’t just experimental — it’s a building block of its operational philosophy. The team uses tools like PentestGPT and DeepAudit to refine exploits, address logic errors, automate post-exploitation workflows, validate exploits, and produce operational documentation. This approach allows the team to scale attacks without requiring a disproportionate number of operators. Combined with open-source offensive frameworks like Metasploit and ysoserial, the team has created an automated intrusion system that can process tens of thousands of targets simultaneously.

The attack chain on Windows systems begins by exploiting known remote code execution ( RCE ) vulnerabilities in websites or vulnerable IIS servers . An automated script then installs malware for SEO fraud or data theft . In select cases , a web shell is deployed , which paves the way for BadIIS and additional backdoors . The group uses batch scripts that leverage certutil to download the privilege escalation tool EfsPotato , the Quasar RAT , and secondary scripts from a remote server. Notably, BadIIS operates under a malware-as-a-service (MaaS) model and is used by multiple Chinese-speaking groups.

UAT-10147: AI-assisted attacks with SPECTRE and Linux Rootkit

To bypass Windows, UAT-10147 uses the BYOVD (Bring Your Own Vulnerable Driver). Specifically, SPECTRE exploits vulnerable drivers such as RTCore64.sys (related to CVE-2019-16098) and DBUtil_2_3.sys (related to CVE-2021-21551) to manipulate kernel callback structures and neutralize endpoint security solutions such as CrowdStrike Falcon, SentinelOne , and Microsoft Defender. This approach allowsthe malware to “blind” kernel-level security tools.

UAT-10147 and SPECTRE: Technical details of the Linux rootkit

On Linux systems, the UAT-10147 attack chain exploits known vulnerabilities for initial access, followed by Local Privilege Escalation (LPE) exploits to gain root. The CVEs used include: CVE-2022-0995, CVE-2021-3156 (Baron Samedit), CVE-2015-5287, CVE-2015-3246, CVE-2010-3904 , and CVE-2022-0847 (Dirty Pipe). This pattern reveals opportunistic exploitation of unpatched server fleets — the team doesn’t need zero-days when there are so many unpatched systems.

See also: Spectre Attack on Cloudflare Workers: JWT Leak (12 Bits/Second)

The Linux rootkit Spectre (companion of the SPECTRE implant) uses the ftrace instrumentation framework instead of the older syscall-table patching method, which makes it significantly more difficult to detect by common rootkit detection tools. The rootkit disguises itself as a legitimate kernel module named acpi_pad.ko, thus hiding its presence from surface inspections. After gaining root-level access, the group deploys backdoors such as Noodle RAT (a variant of Gh0st RAT and Rekoobe), SPECTRE , and Meterpreter for outbound connections to C2 infrastructure.

Among the vulnerabilities exploited by the group during the campaign are: CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441 and CVE-2021-29442 (Alibaba Nacos). The variety of targets demonstrates that the group maintains a wide arsenal of exploits for different technologies and platforms, significantly increasing the number of potential victims.

UAT-10147: AI-assisted attacks with SPECTRE and Linux Rootkit

How to protect yourself from UAT-10147 and similar threats

Organizations that expose Windows or Linux web servers to the internet should take immediate action. Aggressive patching of internet-facing servers is the first line of defense, with particular emphasis on known Local Privilege Escalation vulnerabilities and exposed IIS interfaces . On Windows systems, Microsoft 's vulnerable driver blocklist should be enabled , as well as HVCI or WDAC protections to prevent drivers such as RTCore64.sys and DBUtil_2_3.sys from loading .

EDR systems should be monitored for kernel-callback tampering, suspicious driver loading, and abrupt protection failures, as the Windows component of SPECTRE is specifically designed to blind endpoint tools. On Linux systems, defenders should look for rogue kernel modules, ftrace abuse, persistence via suspicious systemd services, and unusual behavior of web shells or RATs on server hosts. Networks should also check for suspicious staging infrastructure, especially open directories and high-risk ports such as 54321 that connect to the team’s infrastructure.

See also: UAT-7810: New LONGLEASH malware and expansion of the ORB network

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The UAT-10147 case is a prime example of the new generation of cyberthreats, where artificial intelligence is not just a buzzword but a real business advantage for attackers. According to The Hacker News, the group represents a new trend where commodity tools are combined with AI-assisted automation to achieve scale that previously required much larger teams. Integrating logging, asset inventory, and rapid patch management remain critical, given that the campaign relies primarily on known vulnerabilities rather than novel exploits — meaning prevention is entirely possible for organizations that keep their systems up to date.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS