UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platform backdoor, SPECTRE, with advanced anti-analysis techniques and EDR bypass capabilities. The group employs a ‘MaaS’ model with a specific variant of the BadIIS malware, and uses AI tools like DeepAudit and ASP.NET ViewState deserialization guides to identify vulnerabilities and deploy payloads. Their tactics involve SEO fraud, data theft, and blending exfiltration traffic with legitimate SaaS traffic.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
