logo

UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques

ID: a6a99ecd-ceaa-5029-92ce-939709012409

STIX ID: report--a6a99ecd-ceaa-5029-92ce-939709012409

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

UAT-10147, a Chinese-speaking threat actor, is reported to use the SPECTRE backdoor and a Linux rootkit to perform sophisticated multi-platform attacks and employs BYOVD to bypass EDR protections; Cisco Talos analysis highlights AI-assisted code generation and recommends isolating affected servers and conducting kernel-level forensic analysis to prevent lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.