news.mlab.sh
Back to the feed
threat-intel

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

High
Image: The Hacker News
Summary

The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platform backdoor, SPECTRE, with advanced anti-analysis techniques and EDR bypass capabilities. The group employs a ‘MaaS’ model with a specific variant of the BadIIS malware, and uses AI tools like DeepAudit and ASP.NET ViewState deserialization guides to identify vulnerabilities and deploy payloads. Their tactics involve SEO fraud, data theft, and blending exfiltration traffic with legitimate SaaS traffic.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.