UAT-10147 uses AI to scale server attacks and deploys SPECTRE
Source headline: UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Intelligence Summary
Researchers disclosed a Chinese-speaking cybercrime group called UAT-10147 targeting Windows and Linux web servers worldwide. Victims are reported across education, media, technology, and gaming sectors. The article says most targets are located in Brazil, Bolivia, China, Canada, and Vietnam. The group reportedly uses AI to scale server attacks and deploys SPECTRE. The report also mentions an EDR bypass and a Linux rootkit, following discovery of an open investigation lead. Users should review exposure of their web servers and EDR controls and hunt for indicators related to UAT-10147 and SPECTRE.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.