The Chonkerton

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

ai

A Chinese-speaking threat actor known as UAT-10147 is deploying a sophisticated, cross-platform backdoor called SPECTRE. According to Cisco Talos, the malware targets Linux and Windows servers, using advanced techniques to steal credentials and bypass endpoint detection and response systems. Analysis of the recovered source code suggests the group may be using generative AI to help develop its custom rootkits and malware.

Source: https://blog.talosintelligence.com/uat-10147-deploys-spec...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton