UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques
ID: a6a99ecd-ceaa-5029-92ce-939709012409
STIX ID: report--a6a99ecd-ceaa-5029-92ce-939709012409
Feed Name: ThreatCluster
Threat Score
UAT-10147, a Chinese-speaking threat actor, is reported to use the SPECTRE backdoor and a Linux rootkit to perform sophisticated multi-platform attacks and employs BYOVD to bypass EDR protections; Cisco Talos analysis highlights AI-assisted code generation and recommends isolating affected servers and conducting kernel-level forensic analysis to prevent lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
