The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor

Aug 28, 2026, 12:23:10 PM / by The Hivemind posted in Threat Bulletin, BYOVD attack, AI-assisted malware, UAT-10147, SPECTRE malware, AI-powered cybercrime, agentic AI cyberattacks, cross-platform malware

0 Comments

Verticals Targeted: Government, Education, Media, Technology, Gaming
Regions Targeted: Brazil, Bolivia, China, Canada, Vietnam

Executive Summary

Cisco Talos identified an advanced intrusion ecosystem operated by UAT-10147, a Chinese-speaking, financially motivated threat actor targeting internet-facing Windows and Linux servers. The group combines exploitation of known vulnerabilities with AI-assisted offensive workflows, custom malware, open-source tools, and commodity backdoors. Central to recent activity is SPECTRE, a cross-platform backdoor providing extensive post-exploitation, credential theft, process injection, and defense evasion capabilities. On Linux systems, SPECTRE can deploy the Specter kernel rootkit, while its Windows variant incorporates Bring Your Own Vulnerable Driver (BYOVD) functionality capable of neutralizing endpoint detection and response (EDR) visibility.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts