UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Summary

A Chinese-speaking cybercrime group, UAT-10147, is actively targeting Windows and Linux web servers globally, with a significant focus on sectors like education, media, technology, and gaming. The group is employing advanced techniques, including the use of AI to scale server attacks and the deployment of the SPECTRE exploit. Notably, UAT-10147 has demonstrated the ability to bypass Endpoint Detection and Response (EDR) solutions and utilize a Linux rootkit.

IFF Assessment

FOE

The discovery of a sophisticated cybercrime group employing AI for scaled attacks and advanced evasion techniques like EDR bypass and rootkits presents a significant threat to defenders.

Defender Context

Defenders need to be aware of advanced threats like UAT-10147 that leverage AI to enhance attack capabilities and employ techniques designed to evade common security measures. Monitoring for unusual server activity, focusing on EDR effectiveness, and understanding rootkit behaviors are crucial for mitigating these risks.

Read Full Story →