{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/uat-10147/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["UAT-10147"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Internet Information Services"],"_cs_severities":["high"],"_cs_tags":["backdoor","cross-platform","rootkit","byovd","e-commerce-fraud","cybercrime","agentic-ai","web-exploitation","post-compromise"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eUAT-10147 is a Chinese-speaking threat actor targeting internet-facing IIS and Linux servers to conduct SEO fraud and establish persistent access. The actor utilizes a newly identified, custom-developed backdoor called SPECTRE, which demonstrates significant cross-platform capabilities. The malware is notable for its integration of AI-assisted code generation, robust anti-analysis scoring routines, and advanced defense evasion, including Bring Your Own Virtual Driver (BYOVD) to neutralize EDR solutions and custom Linux kernel rootkits.\u003c/p\u003e\n\u003cp\u003eThe SPECTRE implant employs custom obfuscation techniques, including PEB hash walking for API resolution and a per-string xorshift32 PRNG scheme for encryption. Configuration management for the backdoor is uniquely handled via NTFS Alternate Data Streams (ADS) on Windows systems to maintain persistence and C2 agility. The actor's operational maturity is further highlighted by the use of web shells with covert headers (\u0026quot;X-ID\u0026quot;) and SEO fraud utilities, indicating a persistent, monetized post-compromise ecosystem.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial exploitation of internet-facing IIS or Linux servers, likely leveraging AI-assisted vulnerability research.\u003c/li\u003e\n\u003cli\u003eDeployment of the SPECTRE backdoor or secondary web shells (e.g., ASHX SEO engine) to establish initial foothold.\u003c/li\u003e\n\u003cli\u003eExecution of the SPECTRE implant, which performs a local anti-analysis environment check to ensure it is not running in a sandbox or hardened system.\u003c/li\u003e\n\u003cli\u003eEstablishment of C2 communication channels using HTTP POST requests to \u0026quot;/api/v1/register\u0026quot; and \u0026quot;/api/v1/output\u0026quot; with covert \u0026quot;X-ID\u0026quot; headers.\u003c/li\u003e\n\u003cli\u003ePersistence and configuration updates performed by reading/writing to NTFS Alternate Data Streams (ADS) located at \u0026quot;C:\\Windows\\System32\\drivers\\etc\\hosts:cache\u0026quot;.\u003c/li\u003e\n\u003cli\u003eDeployment of BYOVD components or Linux kernel rootkits to neutralize security software and gain kernel-level control.\u003c/li\u003e\n\u003cli\u003eExecution of credential theft and process injection modules to expand control over the target infrastructure.\u003c/li\u003e\n\u003cli\u003eFinal objective: long-term persistence for SEO fraud monetization and persistent access to server resources.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eUAT-10147's activity results in compromised internet-facing servers, leading to unauthorized control, potential data exfiltration, and the subversion of server resources for SEO fraud campaigns. The use of kernel-level rootkits and BYOVD techniques significantly complicates incident response and remediation, as traditional EDR protections are explicitly targeted for neutralization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Sysmon FileCreate and ProcessCreation logging to detect modifications to NTFS Alternate Data Streams (ADS), specifically targeting the \u0026quot;C:\\Windows\\System32\\drivers\\etc\\hosts:cache\u0026quot; path.\u003c/li\u003e\n\u003cli\u003eImplement network-based monitoring for inbound HTTP POST requests containing custom headers such as \u0026quot;X-ID\u0026quot; to identify C2 communication.\u003c/li\u003e\n\u003cli\u003eDeploy detections for BYOVD attacks by monitoring the loading of vulnerable/unsigned drivers known to be abused for EDR neutralization.\u003c/li\u003e\n\u003cli\u003eReview all IIS web directories for unauthorized ASHX files or SEO-related configuration artifacts associated with UAT-10147.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T13:08:22Z","date_published":"2026-08-20T13:08:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-uat10147-spectre/","summary":"The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.","title":"UAT-10147 Deploys SPECTRE Cross-Platform Backdoor","url":"https://feed.craftedsignal.io/briefs/2026-08-uat10147-spectre/"}],"language":"en","title":"CraftedSignal Threat Feed - UAT-10147","version":"https://jsonfeed.org/version/1.1"}