Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

UAT‑10147 Deploys AI‑Scaled Server Attacks with EDR‑Bypassing SPECTRE Rootkit

Researchers identified the Chinese‑speaking cybercrime group UAT‑10147, which leverages AI to mass‑target Windows and Linux web servers and deploys the SPECTRE malware that bypasses EDR and installs a Linux rootkit. The campaign spans education, media, technology and gaming sectors, underscoring a control gap that SOC 2 programs must address.

LiveThreat™ Intelligence · 📅 August 24, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

UAT‑10147 Deploys AI‑Scaled Server Attacks with EDR‑Bypassing SPECTRE Rootkit

What Happened — Researchers have uncovered a Chinese‑speaking cybercrime group, UAT‑10147, that uses artificial‑intelligence to automate the discovery and exploitation of Windows and Linux web servers. The group’s payload, dubbed SPECTRE, evades leading endpoint detection and response (EDR) tools and installs a custom Linux rootkit for long‑term persistence. Campaign activity spans education, media, technology and gaming organizations, with a concentration of targets in Brazil, Bolivia, China, Canada and Vietnam.

Why It Matters for Compliance & Audit Readiness

  • The attack demonstrates a control gap: traditional EDR signatures are insufficient against AI‑generated, file‑less malware, highlighting the need for continuous control mapping and evidence collection.
  • SOC 2 CC3.1 (System Operations) and CC6.1 (Monitoring) require documented processes for detecting and responding to novel threats; without automated evidence, audit evidence can be incomplete.
  • Verisq’s Control Mapping capability can continuously map observed TTPs to SOC 2 controls, providing real‑time audit‑ready evidence of mitigation.

Who Is Affected — Education, media, technology and gaming firms that host public‑facing web servers, as well as cloud‑hosting providers serving those sectors.

Recommended Actions

  • Map SPECTRE’s techniques (AI‑driven scanning, EDR bypass, kernel‑mode rootkit) to SOC 2 CC3.1 and CC6.1 controls.
  • Deploy continuous monitoring tools that capture raw EDR alerts and kernel‑level activity as immutable audit logs.
  • Validate that your EDR solution can detect file‑less behaviors and integrate threat‑intel feeds that flag AI‑generated payloads.
  • Conduct a rapid configuration review of all web‑server images to ensure baseline hardening and patch compliance.

Source: The Hacker News

Technical Notes — The SPECTRE malware chain leverages AI to prioritize vulnerable hosts, uses a novel kernel‑mode rootkit that injects code via undocumented Linux syscalls, and bypasses signature‑based EDR by executing in memory. No public CVE is directly exploited; the attack relies on logic‑based evasion. Source: same article

📰 Original Source
https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →