UAT-10147 Hides SPECTRE Inside Server Intrusions

Cisco Talos says UAT-10147 is using the SPECTRE implant in active intrusions against Microsoft IIS and Linux servers. The tooling combines cross-platform command-and-control, credential theft, and SEO-fraud monetization, while adding Linux rootkit and kernel-level endpoint detection and response (EDR) bypass features. The bypass matters because SPECTRE can use a legitimate signed driver to neutralize security controls at the kernel layer, then keep running below the operating system. That means defenders can see an alert, reboot a host, or clean up the visible malware and still miss the part that keeps the attacker resident and able to reuse stolen credentials. For teams that treat EDR as the containment line on internet-facing servers, the exposure is not just the initial foothold but the control path the operator can still hold after standard cleanup. Talos’ reporting leaves one hard question open: which compromised boxes still have a hidden kernel foothold even after the obvious tools are gone.

Part of the PlainSec briefing for 2026-08-24

Editions

Sources