LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
ai

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

zeroday.news ·

Cybersecurity researchers have reported on a Chinese-speaking cybercrime group, identified as UAT-10147, which is reportedly leveraging artificial intelligence to scale its attacks against web servers. The group is said to be deploying a sophisticated toolkit that includes an EDR bypass mechanism and a Linux rootkit, with a payload referred to as SPECTRE. These attacks are targeting both Windows and Linux environments globally, with a particular focus on the education, media, technology, and gaming sectors.

The reported use of AI by UAT-10147 suggests an attempt to automate and expand the reach of their operations, potentially by assisting in reconnaissance, vulnerability scanning, or payload generation and delivery. While the specific AI applications were not detailed, such capabilities could significantly increase the efficiency and volume of attacks compared to purely manual methods. The group's toolkit includes SPECTRE, which, based on the name, could imply a focus on data exfiltration or a complex multi-stage infection process.

A critical component of UAT-10147's strategy is an EDR (Endpoint Detection and Response) bypass. This mechanism is designed to evade security software that monitors and responds to threats on endpoints. EDR bypasses often exploit weaknesses in EDR agent logic, leverage legitimate system processes, or employ obfuscation techniques to avoid detection, allowing malicious activity to proceed unimpeded. The presence of such a bypass indicates a sophisticated adversary aiming for persistent and covert access.

Furthermore, the group is deploying a Linux rootkit. Rootkits are stealthy types of malicious software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer. A Linux rootkit would grant UAT-10147 deep control over compromised Linux servers, allowing them to maintain persistence, exfiltrate data, or host further malicious infrastructure without being easily discovered by system administrators.

The attacks are reported to be widespread, affecting web servers across various industries. The education, media, technology, and gaming sectors are specifically mentioned as targets, indicating a broad interest in intellectual property, user data, or computational resources. Geographically, the majority of the identified targets are located in Brazil, Bolivia, China, Canada, and Vietnam, suggesting either a strategic focus on these regions or a opportunistic targeting based on vulnerable internet-facing assets.

Mitigation for this class of threat typically involves a multi-layered security approach. Organizations should ensure all web servers, both Windows and Linux, are regularly patched and updated to address known vulnerabilities. Robust EDR solutions should be deployed and continuously monitored, with a focus on behavioral analysis to detect anomalous activity that might indicate a bypass attempt. Furthermore, network segmentation, strong access controls, and regular security audits are crucial to limit the impact of a potential breach and detect rootkit installations.

The disclosure of UAT-10147's activities underscores the evolving landscape of cybercrime, where advanced techniques like AI integration and sophisticated evasion mechanisms are becoming more prevalent. The targeting of critical web server infrastructure across diverse sectors highlights the persistent threat to global digital assets and the ongoing need for vigilance and comprehensive cybersecurity defenses.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Rethinking Application Security for the AI Era

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek.

malware

Android car head units infected with proxy botnet malware through built-in software updaters

A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s the first documented case of malware found on a car head unit with an infection chain specific to that type of device. “It’s worth noting that head unit

patch

Microsoft shares temporary fix for Windows 11 gaming issues

Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]

vulnerability

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about […]

breach

Researchers Uncover Thousands of Leaked AWS Keys

Truffle Security says it found over 9000 publicly accessible and active AWS key pairs

security

Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first on SecurityWeek.