UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

August 24, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Web servers in Education, Media, Technology, and Gaming sectors
Incident: Large-scale compromise of Windows and Linux servers using AI-enhanced automation.
Impact: Kernel-level persistence and unauthorized data access across global infrastructure.
Attacker: UAT-10147
Analysis: UAT-10147 utilizes a hybrid approach of open-source frameworks and AI tools to scale RCE attacks across diverse sectors. The group employs a sophisticated chain involving EfsPotato for privilege escalation and the SPECTRE implant for persistent, stealthy access. The integration of a Linux kernel rootkit allows the actor to bypass security controls and maintain long-term control for SEO fraud and data theft.
Recommendations: Prioritize patching known RCE vulnerabilities on Windows and Linux web servers.; Monitor for suspicious scheduled tasks and unauthorized certutil usage.; Implement kernel-level integrity monitoring to detect rootkit persistence.
Source: The Hacker News / Cisco Talos

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *