THE UAT-10147 cybercrime group, suspected to be Chinese-speaking, employs the SPECTRE cross-platform implant for malware deployment on IIS and Linux servers. The implant effectively uses advanced EDR bypass techniques, including Bring Your Own Vulnerable Driver (BYOVD) tactics and a Linux rootkit. The malware is designed to inject processes and steal credentials, targeting a wide array of victims. Notably, the group may leverage artificial intelligence for malware development.
The impact is significant, as compromised systems are utilized for SEO fraud, manipulating web rankings while disseminating malicious content to users. To counter these threats, organizations should monitor for vulnerable drivers, implement virtualization-based security, and audit Linux endpoints.