← Back
MalwareCisco Talos·5 days ago

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos has identified a new implant called SPECTRE that operates across multiple platforms and combines command-and-control capabilities with process injection, credential harvesting, and anti-analysis defenses. The malware notably features kernel-level EDR bypass functionality and Linux rootkit capabilities, demonstrating an advancement in commodity intrusion frameworks. This tool represents a significant evolution in attack sophistication by integrating both user-space and kernel-level persistence and evasion techniques.

Read full article at Cisco Talos

Related Articles

MalwareThe Hacker News·1 day ago

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

MalwareCisco Talos·5 days ago

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

A Chinese-speaking threat actor tracked as UAT-10147 is leveraging agentic AI capabilities during post-compromise operations against vulnerable web servers across multiple countries. Cisco Talos analyzed the group's campaign, documenting their attack chain, BadIIS infection tactics, and the broader geographic scope and potential impact of their operations.

MalwareHelp Net Security·9 hours ago

Fake OpenAI Codex download tricks macOS users into installing malware

A malware campaign discovered by Cato Networks exploits sponsored search ads to direct macOS users to a fake OpenAI Codex download page, where victims are socially engineered into pasting malicious commands directly into Terminal. The attack uses a variation of the ClickFix technique, which manipulates users into executing the infection themselves rather than opening a malicious file, with the campaign beginning through sponsored search results for queries like "codex macos download."

MalwareThe Hacker News·10 hours ago

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Researchers have identified a novel command-and-control technique where threat actors exploit FTP banners as dead drop resolvers to deliver two previously unreported RATs named E4del and PINHOLE. This approach leverages legitimate FTP services to obscure malware communications and point to additional C2 infrastructure while evading detection.