UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Key Points:
- Cybersecurity researchers have uncovered a Chinese-speaking cybercrime group named UAT-10147 targeting Windows and Linux web servers worldwide, primarily in education, media, technology, and gaming sectors, with most targets in Brazil, Bolivia, China, Canada, and Vietnam.
- UAT-10147 exploits publicly known vulnerabilities to gain initial access, using AI-powered tools like DeepAudit and PentestGPT to automate reconnaissance, exploitation, payload generation, and persistence, while conducting SEO fraud and data theft.
- The group deploys sophisticated malware including the cross-platform SPECTRE backdoor, which features kernel-level rootkits, anti-analysis techniques, and the ability to bypass major endpoint detection and response (EDR) solutions using vulnerable drivers.
- Attack chains involve multiple stages such as privilege escalation with tools like EfsPotato, deployment of web shells and RATs (e.g., Quasar RAT, Gh0stCringe), and blending exfiltration traffic with legitimate cloud services to evade detection.
- The Linux variant of SPECTRE includes a kernel module rootkit providing persistent control and evasion capabilities, suspected to be developed with AI assistance, highlighting the group's advanced offensive tradecraft and operational scale.