A Chinese-speaking cybercrime group, UAT-10147, is actively targeting Windows and Linux web servers across various sectors globally, with significant activity in Brazil, Bolivia, China, Canada, and Vietnam. This sophisticated threat actor leverages publicly disclosed vulnerabilities for initial access and employs a mix of open-source offensive frameworks like Metasploit and PentestGPT, along with AI-powered tools, to automate intrusion operations, achieve persistence, conduct SEO fraud, and steal data.
UAT-10147's attack chains involve exploiting known flaws to achieve remote code execution (RCE) on web or IIS servers, followed by deploying malware such as BadIIS, Quasar RAT, Gh0stCringe, and a newly identified cross-platform implant named SPECTRE. They utilize privilege escalation tools like EfsPotato, establish deceptive scheduled tasks for persistence, and employ advanced evasion techniques, including configuring Microsoft Defender exclusions and deleting initial payloads. Notably, the core BadIIS malware operates under a malware-as-a-service (MaaS) model, indicating collaboration among Chinese-speaking groups.
A distinguishing feature of UAT-10147's tradecraft is its deep integration of AI, using tools like DeepAudit for vulnerability scanning and PentestGPT for autonomous pentesting and exploit execution. The SPECTRE implant, a C-written cross-platform backdoor, showcases significant evolution in intrusion tooling. It incorporates sophisticated obfuscation, anti-analysis, process injection, credential theft, and kernel-level EDR bypass functionality via BYOVD (using vulnerable drivers like RTCore64.sys and DBUtil_2_3.sys). On Linux, SPECTRE deploys a kernel-level rootkit called "Specter," suspected to be developed with AI assistance, granting persistent, kernel-level control and blinding major EDR solutions.
Top comments (0)