UAT-10147 Uses AI to Deploy SPECTRE

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- UAT-10147 targeted Windows and Linux web servers across education, media, technology, and gaming sectors, with most observed targets in Brazil, Bolivia, China, Canada, and Vietnam.
- UAT-10147 divided a target list of approximately 170,000 URLs into 17 files of about 10,000 each; the top listed destinations were the U.S., India, the U.K., Germany, and the Netherlands.
- UAT-10147 used AI to refine exploits, troubleshoot logic, automate post-exploitation workflows, validate vulnerabilities, generate operational documentation, and conduct reconnaissance.
- SPECTRE is a cross-platform C backdoor supporting up to 45 Windows commands and 29 Linux commands, with anti-analysis controls, credential theft, process injection, and a Linux kernel rootkit.
- SPECTRE uses vulnerable drivers to unlink EDR callbacks, leaving security products including CrowdStrike Falcon, SentinelOne, and Microsoft Defender unable to observe new processes, threads, and image loads for the session.
- BadIIS is deployed alongside tools including Gh0stCringe, Quasar RAT, EfsPotato, and web shells, while stolen data is routed through legitimate cloud configuration services to blend with administrative traffic.
Why it matters: For server defenders, UAT-10147 combined AI-assisted scaling with a 170,000-URL target list, cross-platform SPECTRE malware, and kernel-level EDR bypass. That combination gives the group automated intrusion workflows while making Windows and Linux compromise harder to detect after access is established.
Ask SkimNews

