UAT-10147 Hackers Deploy AI-Powered SPECTRE Backdoor on Servers — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- UAT-10147, a Chinese-speaking cybercrime group, targets Windows and Linux web servers across the education, media, technology, and gaming sectors, with the vast majority of compromised hosts located in Brazil, Bolivia, China, Canada, and Vietnam.
- Cisco Talos uncovered an exposed open directory at "139.180.197[.]150" containing a target list of approximately 170,000 URLs split into 17 batches of about 10,000 each; the top destinations on that list are the U.S., India, the U.K., Germany, and the Netherlands.
- The attacker integrates AI tools throughout the kill chain — DeepAudit for vulnerability scanning, PentestGPT for autonomous pentesting, an ASP.NET ViewState deserialization guide, and four custom Python scripts for post-exploitation diagnostics and traffic blending.
- SPECTRE, a new cross-platform C-based backdoor first deployed in April 2026, supports 45 Windows commands and 29 Linux commands; the Windows version uses BYOVD with MSI's RTCore64.sys and Dell's DBUtil_2_3.sys to unlink EDR callbacks and neutralize CrowdStrike Falcon, SentinelOne, and Microsoft Defender visibility.
- The Linux variant of SPECTRE ships with an integrated kernel-module rootkit called Specter and triggers self-termination via a weighted sandbox-detection scoring system that exceeds 50 points based on process names, RAM, CPU, and known sandbox hostnames.
- The campaign exploits a long list of known flaws for initial access and privilege escalation, including Zimbra (CVE-2022-27925), Telerik UI (CVE-2019-18935), Alibaba Nacos (CVE-2021-29441/29442), and Dirty Pipe (CVE-2022-0847), then routes exfiltrated data through Alibaba Nacos instances to blend traffic with legitimate admin operations.
Why it matters: SPECTRE's BYOVD-driven EDR bypass explicitly unhooks kernel callbacks for CrowdStrike Falcon, SentinelOne, and Microsoft Defender, leaving those products blind to new process, thread, and image-load events on infected hosts — a material degradation of detection for any enterprise running those tools. Combined with the actor's reliance on a MaaS BadIIS variant shared across Chinese-speaking groups and ~170,000 queued targets, the tradecraft is built for commoditized, high-volume compromise rather than bespoke espionage.
Ask SkimNews




