ZeroHour
Cisco Talospublished ()ingested Joey Chen

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

mediumThreat actor exploited in the wildimportance 50
AI summary · glm-5.3-flash

Cisco Talos identifies UAT-10147 deploying the SPECTRE implant with cross-platform C2, credential theft, and kernel-level EDR bypass.

Cisco Talos reports that the tracked threat actor UAT-10147 is deploying a newly identified implant named SPECTRE. SPECTRE supports cross-platform command-and-control, process injection, credential theft, and anti-analysis protections. It also includes a Linux rootkit and BYOVD (bring your own vulnerable driver) capability enabling kernel-level EDR bypass, marking an evolution in commodity intrusion tooling.

  • SPECTRE implant offers cross-platform C2 operations
  • Includes Linux rootkit and BYOVD EDR bypass
  • Process injection and credential theft capabilities included
  • Represents evolution in commodity intrusion tooling
ProductsSPECTRE
Threat actorsUAT-10147
MalwareSPECTRE
Full article

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

This source does not provide full text. Read it at blog.talosintelligence.com.