<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>E-Commerce-Fraud - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/e-commerce-fraud/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 20 Aug 2026 13:08:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/e-commerce-fraud/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>UAT-10147 Deploys SPECTRE Cross-Platform Backdoor</title><link>https://feed.craftedsignal.io/briefs/2026-08-uat10147-spectre/</link><pubDate>Thu, 20 Aug 2026 13:08:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-uat10147-spectre/</guid><description>The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.</description><content:encoded><![CDATA[<p>UAT-10147 is a Chinese-speaking threat actor targeting internet-facing IIS and Linux servers to conduct SEO fraud and establish persistent access. The actor utilizes a newly identified, custom-developed backdoor called SPECTRE, which demonstrates significant cross-platform capabilities. The malware is notable for its integration of AI-assisted code generation, robust anti-analysis scoring routines, and advanced defense evasion, including Bring Your Own Virtual Driver (BYOVD) to neutralize EDR solutions and custom Linux kernel rootkits.</p>
<p>The SPECTRE implant employs custom obfuscation techniques, including PEB hash walking for API resolution and a per-string xorshift32 PRNG scheme for encryption. Configuration management for the backdoor is uniquely handled via NTFS Alternate Data Streams (ADS) on Windows systems to maintain persistence and C2 agility. The actor's operational maturity is further highlighted by the use of web shells with covert headers (&quot;X-ID&quot;) and SEO fraud utilities, indicating a persistent, monetized post-compromise ecosystem.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial exploitation of internet-facing IIS or Linux servers, likely leveraging AI-assisted vulnerability research.</li>
<li>Deployment of the SPECTRE backdoor or secondary web shells (e.g., ASHX SEO engine) to establish initial foothold.</li>
<li>Execution of the SPECTRE implant, which performs a local anti-analysis environment check to ensure it is not running in a sandbox or hardened system.</li>
<li>Establishment of C2 communication channels using HTTP POST requests to &quot;/api/v1/register&quot; and &quot;/api/v1/output&quot; with covert &quot;X-ID&quot; headers.</li>
<li>Persistence and configuration updates performed by reading/writing to NTFS Alternate Data Streams (ADS) located at &quot;C:\Windows\System32\drivers\etc\hosts:cache&quot;.</li>
<li>Deployment of BYOVD components or Linux kernel rootkits to neutralize security software and gain kernel-level control.</li>
<li>Execution of credential theft and process injection modules to expand control over the target infrastructure.</li>
<li>Final objective: long-term persistence for SEO fraud monetization and persistent access to server resources.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>UAT-10147's activity results in compromised internet-facing servers, leading to unauthorized control, potential data exfiltration, and the subversion of server resources for SEO fraud campaigns. The use of kernel-level rootkits and BYOVD techniques significantly complicates incident response and remediation, as traditional EDR protections are explicitly targeted for neutralization.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable Sysmon FileCreate and ProcessCreation logging to detect modifications to NTFS Alternate Data Streams (ADS), specifically targeting the &quot;C:\Windows\System32\drivers\etc\hosts:cache&quot; path.</li>
<li>Implement network-based monitoring for inbound HTTP POST requests containing custom headers such as &quot;X-ID&quot; to identify C2 communication.</li>
<li>Deploy detections for BYOVD attacks by monitoring the loading of vulnerable/unsigned drivers known to be abused for EDR neutralization.</li>
<li>Review all IIS web directories for unauthorized ASHX files or SEO-related configuration artifacts associated with UAT-10147.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>backdoor</category><category>cross-platform</category><category>rootkit</category><category>byovd</category><category>e-commerce-fraud</category><category>cybercrime</category><category>agentic-ai</category><category>web-exploitation</category><category>post-compromise</category></item></channel></rss>