VMTech
Discuss a project

UAT-10147 scales server intrusions with AI tools and SPECTRE

UAT-10147 scales server intrusions with AI tools and SPECTRE

UAT-10147 combines public exploits with AI-assisted tooling

Cisco Talos has detailed activity by UAT-10147, a Chinese-speaking cybercrime group targeting Windows and Linux web servers in education, media, technology and gaming. The group uses publicly disclosed vulnerabilities for initial access, then deploys tools for SEO fraud, data theft and persistent access. Talos found a target list of approximately 170,000 URLs, divided into 17 files of about 10,000 URLs each.

The observed victim set was concentrated in Brazil, Bolivia, China, Canada and Vietnam, while the five most common destinations in the target list were the United States, India, the United Kingdom, Germany and the Netherlands. The campaign relies on remote code execution against websites or vulnerable IIS servers, followed by automated scripts that install malware.

Talos said UAT-10147 combines open-source offensive tools including Metasploit, ysoserial, PentestGPT and DeepAudit with privilege-escalation exploits. The actor uses AI-powered tools to refine and validate exploits, automate reconnaissance and post-exploitation work, generate payloads, troubleshoot logic and produce operational documentation.

Windows chains add persistence and weaken endpoint visibility

In one Windows sequence, a batch script uses certutil to download EfsPotato, further scripts and Quasar RAT. EfsPotato is used to obtain elevated privileges and configure Microsoft Defender exclusions, after which the initial payloads are deleted. A deceptive scheduled task named Google Chrome Start silently launches Quasar RAT, while another script installs BadIIS.

BadIIS is a malware-as-a-service variant already associated with multiple Chinese-speaking cybercrime groups. UAT-10147 has also deployed Gh0stCringe and the previously unreported SPECTRE implant. In selected cases, the actor installs an ASHX web shell on an IIS server, enabling continued access before further backdoors are deployed.

SPECTRE is a cross-platform C backdoor that communicates with command-and-control infrastructure over HTTPS. The Windows version supports file operations, keystroke recording, screenshots, shell commands, process control, timestamp modification, shellcode injection, process hollowing and Early Bird APC injection. Talos traced the actor's first use of SPECTRE to April 2026.

Linux attacks culminate in a kernel-level rootkit

On Linux, UAT-10147 exploits known flaws for access and uses local privilege-escalation vulnerabilities including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904 and CVE-2022-0847 to reach root. The actor has then deployed Noodle RAT, SPECTRE and Meterpreter for outbound command-and-control connections.

The Linux SPECTRE variant provides 29 commands for file manipulation, host and process reconnaissance, agent management and unrestricted shell execution. Its most consequential component is Specter, a kernel-module rootkit. Talos said this rootkit can provide persistent kernel-level control that survives reboots and avoids most user-level security controls.

On Windows, SPECTRE can use the vulnerable RTCore64.sys and DBUtil_2_3.sys drivers in a BYOVD technique to terminate security processes. Talos said targeted kernel writes unlink registered EDR callbacks, reducing visibility into process, thread and image-load events for the session.

What server operators should take from the activity

The campaign weaponized vulnerabilities in Zimbra, AjaxPro, Telerik UI for ASP.NET AJAX and Alibaba Nacos, among others. Talos also observed exfiltration routed through a legitimate cloud-based configuration management service, allowing the attackers to blend traffic with administrative operations and poll their own Nacos instance for exploitation results.

For businesses operating internet-facing servers, the practical implication is to prioritize remediation of known web application and local privilege-escalation flaws, inspect IIS and Linux hosts for unauthorized persistence, and investigate anomalous HTTPS traffic, endpoint exclusions and privileged scheduled tasks.

#cybersecurity#serversecurity#linuxsecurity#threatintel
Open analytics
On the site 0 views
min read 5 24.08.2026
Instagram

UAT-10147 scales server intrusions with AI tools and SPECTRE

Open the post on Instagram ↗