Threat · curated 20 Aug 2026

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Coverage timeline

20 Aug 2026talosintelligence.comprimary

Why it matters

UAT-10147 shows adversaries operationalizing generative and agentic AI to accelerate malware creation and post-compromise operations at scale, a trend defenders must factor into threat models for AI-weaponized intrusion tooling.

Cisco Talos reports that UAT-10147, a Chinese-speaking intrusion actor, has integrated AI-assisted development and agentic AI into its post-compromise operations, deploying the cross-platform SPECTRE implant and a Linux 'Specter' rootkit with BYOVD-based EDR neutralization, credential theft, and in-memory web shells. Analysis of recovered source code suggests portions of the rootkit and backdoor were built with AI-assisted code-generation workflows to accelerate offensive malware development.