securityonline.info 8/31/2026, 8:32:38 AM · external

UAT 10147 uses SPECTRE implant to hit IIS, Linux servers

UAT 10147 uses SPECTRE implant to hit IIS, Linux servers
CyberSIXT Evidence Panel
Threat Actor
UAT-10147

THE UAT-10147 cybercrime group, suspected to be Chinese-speaking, employs the SPECTRE cross-platform implant for malware deployment on IIS and Linux servers. The implant effectively uses advanced EDR bypass techniques, including Bring Your Own Vulnerable Driver (BYOVD) tactics and a Linux rootkit. The malware is designed to inject processes and steal credentials, targeting a wide array of victims. Notably, the group may leverage artificial intelligence for malware development.

The impact is significant, as compromised systems are utilized for SEO fraud, manipulating web rankings while disseminating malicious content to users. To counter these threats, organizations should monitor for vulnerable drivers, implement virtualization-based security, and audit Linux endpoints.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline