Interestana
Home/News/UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group, identified as UAT-10147, which is employing artificial intelligence to scale its attacks against Windows and Linux web servers worldwide. The group's operations span multiple sectors, including education, media, technology, and gaming. The primary geographical targets for UAT-10147's malicious activities are located in Brazil, Bolivia, China, Canada, and Vietnam, indicating a broad international reach.

This threat activity came to light following the discovery of an open-source intelligence (OSINT) tool that UAT-10147 was using to identify potential targets. The group has demonstrated a high level of technical sophistication, utilizing advanced techniques such as the SPECTRE exploit, which is designed to extract sensitive data from memory. Furthermore, UAT-10147 has developed capabilities to bypass Endpoint Detection and Response (EDR) solutions, a critical component of modern cybersecurity defenses, allowing their malware to operate undetected. The group also deploys a custom Linux rootkit, which provides persistent, privileged access to compromised systems, enabling them to maintain control and exfiltrate data over extended periods.

The use of AI by UAT-10147 represents a significant escalation in cybercrime capabilities. AI can automate the process of identifying vulnerabilities, crafting tailored exploits, and managing botnets, thereby increasing the speed, scale, and effectiveness of attacks. This allows threat actors to compromise a larger number of servers more efficiently than traditional manual methods. The group's ability to adapt and integrate cutting-edge techniques, such as EDR bypass and advanced rootkits, highlights the evolving threat landscape and the challenges faced by cybersecurity professionals in defending against sophisticated adversaries.

Researchers have not yet disclosed the specific AI models or tools UAT-10147 is employing, nor the exact nature of the OSINT tool used for target reconnaissance. However, the group's operational methodology suggests a well-resourced and technically adept organization. The implications of such advanced AI-driven attacks are far-reaching, potentially impacting critical infrastructure, sensitive data repositories, and the operational continuity of businesses across various industries. The ongoing analysis by cybersecurity firms aims to provide further insights into UAT-10147's infrastructure, tactics, techniques, and procedures (TTPs) to develop more effective countermeasures.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next