UAT-10147 Hackers Use AI to Deploy SPECTRE Backdoor

UAT-10147 hacker group deploying SPECTRE backdoor using AI-driven attack vectors

A sophisticated Chinese-speaking hacker collective, designated UAT-10147, has weaponized artificial intelligence, transforming it from a rudimentary coding assistant into a formidable attack instrument. These malicious actors deploy AI agents to hunt for vulnerabilities, forge exploitation tools, verify their operational efficacy, and assist in establishing persistent footholds on compromised servers. Furthermore, their custom-engineered SPECTRE backdoor possesses the alarming capability to neutralize Windows security defenses and conceal itself deep within the Linux kernel.

The Global Reach of UAT-10147

Security specialists at Cisco Talos initially uncovered this group in early 2026. UAT-10147 aggressively targets internet-facing servers belonging to government organizations, universities, media outlets, technology firms, and gaming corporations. Analysts have identified confirmed infections across Brazil, Bolivia, China, Canada, and Vietnam. Chillingly, upon investigating a server controlled by the attackers, specialists discovered a massive hit list containing approximately 170,000 potential target addresses.

Primary Objectives: Data Theft and SEO Manipulation

The principal objectives of UAT-10147 encompass massive data exfiltration and the manipulation of search engine results. Following a successful system intrusion, the attackers install malicious modules like BadIIS or their proprietary SeoEngineHandler. These insidious modules covertly alter website content presented to search engine crawlers and actively redirect legitimate visitors. Notably, one specific variant specifically targets Vietnam, actively recognizing the regional Cốc Cốc search engine.

A Diverse and Lethal Arsenal

Operating within Windows environments, the group utilizes tools such as EfsPotato, GodPotato, JuicyPotato, and RustPotato to rapidly escalate privileges. They subsequently add IIS directories to the Microsoft Defender exclusion list, forge a new administrator account, and firmly establish remote access. Researchers have also observed the deployment of QuasarRAT and Gh0stCringe during these localized attacks.

Conversely, when targeting Linux systems, the attackers exploit well-known vulnerabilities, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847. Following successful exploitation, they typically install SPECTRE, Noodle RAT, or a Meterpreter payload.

The SPECTRE Backdoor

The C-based SPECTRE backdoor, compatible with both Windows and Linux, holds a prominent position within their lethal arsenal. The Windows iteration robustly supports 45 distinct commands. It can execute arbitrary programs, intercept keystrokes, capture screenshots, harvest Chrome and Edge credentials, extract registry data, and seamlessly inject malicious code into running processes. Prior to execution, the malware astutely evaluates its environment for signs of virtualization, immediately terminating its operation if it suspects analytical scrutiny.

Furthermore, SPECTRE possesses the capability to disable attack detection mechanisms by exploiting vulnerable drivers, specifically RTCore64.sys and DBUtil_2_3.sys, which are linked to CVE-2019-16098 (7.8 High) and CVE-2021-21551 (8.8 High). By acquiring the ability to manipulate the Windows kernel memory, the backdoor effectively neutralizes the very functions security products rely upon to monitor process creation, thread generation, and software module loading.

The Linux variant of SPECTRE features 29 commands and stealthily installs the Specter rootkit, masquerading as the benign acpi_pad.ko kernel module. Specter meticulously conceals processes and its own module, escalates its privileges to root, and executes during every system boot via the hardware-monitor.service. To intercept vital system functions, the rootkit leverages the standard ftrace mechanism, facilitating highly covert modifications to the kernel.

Integrating AI into the Attack Chain

Crucially, UAT-10147 deploys AI directly during active attack sequences. Specialists discovered instances of DeepAudit and PentestGPT operating directly on the group’s command and control server. The AI system actively generated instructions and scripts to exploit ASP.NET ViewState deserialization errors, verified write permissions, diagnosed operational failures, downloaded the SPECTRE payload, and constructed a functioning web shell. Talos also discovered compelling evidence suggesting an AI machine generated the Specter code, alongside traces of an “AI” directory within the environment where the attackers compiled their bespoke tools.

According to Cisco Talos’s assessment, the sophisticated attacks orchestrated by UAT-10147 clearly demonstrate that AI is rapidly transitioning from a mere coding assistant to a driver of semi-autonomous cyberattacks. The model actively assists in target reconnaissance, refines exploitation methodologies, troubleshoots errors, verifies attack outcomes, and prepares advanced tools. This terrifying evolution significantly reduces the manual labor and technical expertise a malicious actor requires to execute a highly complex cyberattack.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply