Threat · curated 20 Aug 2026
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
First reported · updated · 3 reports talosintelligence.com
Coverage timeline
Why it matters
UAT-10147 demonstrates a real-world shift from AI-assisted scripting toward semi-autonomous offensive orchestration, showing defenders that adversaries are now using agentic AI to accelerate malware development and scale intrusion campaigns.
Cisco Talos reports that UAT-10147, a Chinese-speaking intrusion actor, is integrating agentic AI and AI-assisted code generation into its offensive operations against IIS and Linux servers, deploying the new cross-platform SPECTRE implant with a Linux rootkit, BYOVD-based EDR bypass, and in-memory web shells. Talos assesses that AI-driven exploit refinement, payload generation, validation, and post-exploitation automation let the actor scale complex attacks (a target list of ~170,000 URLs) while lowering required expertise.
Summary
Cisco Talos attributes an evolving multi-platform intrusion campaign to UAT-10147, a highly capable Chinese-speaking actor that targets internet-facing IIS and Linux servers, monetizing access through SEO fraud while maintaining advanced persistence and defense-evasion capabilities.[0]
The centerpiece of this campaign is SPECTRE, a newly identified cross-platform backdoor written in C that integrates cross-platform C2, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass, with a companion Linux kernel rootkit named Specter.[0]
The actor combines custom malware with open-source offensive tooling, Bring Your Own Vulnerable Driver EDR neutralization, Linux kernel rootkits, and in-memory web shells, and Talos assesses portions of SPECTRE and Specter show indications of AI-assisted development.[0]
This activity builds on Talos's earlier reporting that UAT-10147 operationalized AI-assisted exploitation workflows to compromise Windows and Linux web servers at scale across government, education, media, technology, and gaming sectors.[1]
Attack chain
- Initial access: UAT-10147 compromises internet-facing IIS and Linux web servers, leveraging publicly disclosed vulnerabilities to gain access at scale as documented in Talos's prior reporting.[0][1]
- Web shell / in-memory foothold: On IIS servers the actor deploys a two-layer web shell whose loader uses in-memory dynamic compilation via CodeDomProvider, and covert authentication via the X-ID header (or v parameter) requiring the token 'x9', returning a deceptive 404 otherwise.[0]
- Privilege escalation: The actor uses multiple 'Potato' family tools (GodPotato, JuicyPotato, EfsPotato, RustPotato) and SPECTRE's named-pipe impersonation and getsystem routines to obtain SYSTEM privileges.[0]
- Implant deployment: SPECTRE is deployed cross-platform; the Windows variant self-hollows into RuntimeBroker.exe on startup, and the Linux variant runs an eight-factor anti-sandbox check before beaconing to a hardcoded C2.[0]
- Credential theft: SPECTRE dumps SAM/SYSTEM/SECURITY hives, enumerates Credential Manager via cmdkey, and copies Chrome/Edge login data for offline DPAPI decryption.[0]
- Defense evasion (BYOVD / rootkit): On Windows, SPECTRE loads a vulnerable driver (RTCore64 or DBUtil) to unlink EDR kernel callbacks; on Linux it loads the Specter kernel rootkit disguised as acpi_pad.ko using ftrace hooks to hide processes and modules and escalate to UID 0.[0][3][4]
- Persistence: The actor establishes persistence via a fraudulent systemd unit (hardware-monitor.service configured Before=sysinit.target), Windows service installers, and commodity backdoors including Gh0stCringe, QuasarRAT, Meterpreter, and Noodle RAT.[0]
- Monetization: Compromised IIS servers are used for SEO fraud through BadIIS MaaS and a C# ASHX SEO engine that serves fabricated content to crawlers and malicious JavaScript to targeted (Vietnamese) users.[0]
Disclosure timeline
| Date | Event |
|---|---|
| 2026-08-20 | Cisco Talos published its analysis of UAT-10147 deploying the SPECTRE cross-platform implant with Linux rootkit and BYOVD capabilities.[0] |
| 2026-08-20 | Talos concurrently published its companion report on UAT-10147 integrating agentic AI into post-compromise operations, first documenting the actor and campaign.[1] |
Actor profile
UAT-10147
A highly capable Chinese-speaking, financially motivated intrusion actor targeting internet-facing IIS and Linux web servers globally, combining SEO fraud monetization with custom malware (SPECTRE backdoor, Specter rootkit), open-source offensive tooling, and BYOVD EDR neutralization. The actor shows operational maturity and is progressively incorporating AI-assisted development. Talos assesses with medium confidence that SEO fraud components are associated with the 'x神' (xshen) actor, and QuasarRAT campaign IDs and SEO targeting indicate a focus on Vietnamese users.[0][1]
How it works
SPECTRE's Windows BYOVD EDR-killer downloads a well-known vulnerable driver from C2 — RTCore64.sys from MSI (CVE-2019-16098) or DBUtil_2_3.sys from Dell (CVE-2021-21551) — writes it to %TEMP%, installs it as a transient kernel service via the SCM, and opens an IOCTL handle to obtain arbitrary kernel read/write primitives.[0][3][4]
Using the arbitrary kernel R/W, SPECTRE calls NtQuerySystemInformation to locate ntoskrnl.exe, references a hardcoded per-build offset table covering 13 Windows versions to compute the addresses of PspCreateProcessNotifyRoutine, PspCreateThreadNotifyRoutine, and PspLoadImageNotifyRoutine, and unlinks each registered EDR callback from its doubly-linked list, blinding callback-dependent EDR products.[0]
The Specter Linux rootkit hooks six syscall handlers (tcp6_seq_show, tcp4_seq_show, tkill, tgkill, kill, getdents64) using the kernel's native ftrace framework with FTRACE_OPS_FL_IPMODIFY rather than patching the syscall table, minimizing kernel-integrity noise; the user-level implant controls it via kill() syscalls to magic PID 0x7A69 (31337) with real-time signals 62 (hide process), 36 (hide module), 37 (escalate to UID 0), and 35 (load handshake).[0]
SPECTRE evades static analysis via runtime API resolution through PEB hash walking (DJB2 variant), per-string xorshift32 PRNG string encryption with unique 32-bit compile-time seeds decrypted to thread-local storage, and a weighted anti-analysis scoring routine that self-terminates when the score reaches 50.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| MSI RTCore64.sys driver (abused via BYOVD) | Vulnerable driver associated with CVE-2019-16098 | Legitimate vulnerable driver abused by the implant; defenders should block/monitor the driver rather than patch the implant.[0][3] |
| Dell DBUtil_2_3.sys driver (abused via BYOVD) | Vulnerable driver associated with CVE-2021-21551 | Legitimate vulnerable driver abused by the implant; defenders should block/monitor the driver.[0][4] |
| Windows and Linux internet-facing web servers (IIS / Linux) | Targeted by UAT-10147 SPECTRE deployment; exact server software versions not specified in the evidence. | Not specified.[0][1] |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| ip | 139.180.197.150 | Download server observed communicating with a compromised machine, leading Talos to identify UAT-10147 activity.[1] |
| file-path | C:\Windows\System32\drivers\etc\hosts:cache | NTFS Alternate Data Stream used by a SPECTRE variant to read/update its C2 configuration, circumventing firewall blocklists.[0] |
| file-path | acpi_pad.ko | Filename used to disguise the deployed Specter Linux kernel rootkit as the legitimate ACPI processor power-management module.[0] |
| other | hardware-monitor.service (systemd unit, description 'Hardware Performance Monitor', Before=sysinit.target) | Fraudulent systemd persistence unit ensuring the Specter rootkit executes on every boot before security tooling.[0] |
| other | \\.\pipe\spectre_ | Named pipe created by SPECTRE for named-pipe impersonation to acquire a SYSTEM token.[0] |
| other | HTTP endpoints /api/v1/register and /api/v1/output | SPECTRE C2 communication endpoints reached via HTTP POST.[0] |
| other | X-ID HTTP header carrying token 'x9' | Covert web shell authentication token; requests lacking it (or v=x9) receive a deceptive 404.[0] |
| domain | vn.xyz | C2 domain suffix used by the ASHX SEO engine (SeoEngineHandler) targeting Vietnamese users.[0] |
| file-path | C:\Users\Administrator\Desktop\2025-11-21 (x神订制全站劫持按浏览器语言跳转)\dll\Release\demo.pdb | PDB path embedded in BadIIS samples linking the SEO tooling to the 'x神' (xshen) actor.[0] |
| file-path | C:\Users\iis\Desktop\AI\EfsPotatoCpp\x64\Release\EfsPotato.pdb | PDB path in custom-compiled EfsPotato privilege-escalation tool exposing the actor's AI-directory build environment.[0] |
| cve | CVE-2019-16098 | Vulnerability in MSI RTCore64.sys driver abused by SPECTRE's BYOVD EDR-killer.[0][3] |
| cve | CVE-2021-21551 | Vulnerability in Dell DBUtil_2_3.sys driver abused by SPECTRE's BYOVD EDR-killer.[0][4] |
Key takeaways
- SPECTRE represents a significant evolution in commodity intrusion tooling, unifying cross-platform C2, process injection, credential theft, BYOVD-based EDR neutralization, and a Linux kernel rootkit in a single implant.[0]
- UAT-10147 demonstrates operational maturity by blending custom malware with open-source frameworks and increasingly incorporating AI-assisted development into its tooling, including SPECTRE and the Specter rootkit.[0]
- The campaign monetizes access to compromised IIS/Linux servers through SEO fraud aimed at Vietnamese users while maintaining stealthy kernel-level persistence, underscoring the need for both web-server hardening and kernel/driver-level defenses.[0][1]
Defensive actions
- Deploy the Cisco Talos ClamAV signatures and SNORT rules provided for this threat and hunt using the published IOC list.: Talos published specific ClamAV signatures (including Unix.Rootkit.Spectre and Win.Malware.BadIIS) and SNORT SIDs that detect and block SPECTRE, Specter, and associated tooling.[0][11]
- Block and monitor for the known vulnerable drivers RTCore64.sys and DBUtil_2_3.sys via driver blocklists.: SPECTRE's BYOVD EDR-killer relies on loading these drivers to gain kernel R/W and unlink EDR callbacks, so blocking them neutralizes the kernel-blinding capability.[0][3][4]
- Audit Linux systemd units for a fraudulent hardware-monitor.service and inspect for kernel modules disguised as acpi_pad.ko, checking /proc/sys/kernel/tainted and ftrace-based hooks.: The Specter rootkit persists via a systemd unit configured Before=sysinit.target and hides itself using ftrace hooks, evading standard user-level controls.[0]
- Inspect IIS request pipelines and web handlers for reflection-based hijacking and in-memory compiled web shells authenticating via the X-ID header token 'x9'.: The actor deploys an ASHX SEO engine and a two-layer in-memory web shell that blend control traffic into routine HTTP requests to evade detection.[0]
- Monitor for NTFS Alternate Data Streams such as hosts:cache used to store C2 configuration.: A SPECTRE variant reads its C2 config from an ADS to update infrastructure without recompiling and to bypass firewall blocklists.[0]