Threat · curated 20 Aug 2026
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
First reported · updated · 2 reports talosintelligence.com
Coverage timeline
Why it matters
UAT-10147 shows adversaries operationalizing generative and agentic AI to accelerate malware creation and post-compromise operations at scale, a trend defenders must factor into threat models for AI-weaponized intrusion tooling.
Cisco Talos reports that UAT-10147, a Chinese-speaking intrusion actor, has integrated AI-assisted development and agentic AI into its post-compromise operations, deploying the cross-platform SPECTRE implant and a Linux 'Specter' rootkit with BYOVD-based EDR neutralization, credential theft, and in-memory web shells. Analysis of recovered source code suggests portions of the rootkit and backdoor were built with AI-assisted code-generation workflows to accelerate offensive malware development.