Updated
Updated · The Hacker News · Aug 24
UAT-10147 Scales 170,000-URL Server Attacks, Deploying SPECTRE With EDR Bypass and Linux Rootkit
Updated
Updated · The Hacker News · Aug 24

UAT-10147 Scales 170,000-URL Server Attacks, Deploying SPECTRE With EDR Bypass and Linux Rootkit

3 articles · Updated · The Hacker News · Aug 24

Summary

  • Cisco Talos said UAT-10147 targeted Windows and Linux web servers worldwide, using AI-assisted tooling to automate exploitation, reconnaissance, persistence and data theft across education, media, technology and gaming victims.
  • About 170,000 URLs were found in the actor’s target list, and the group used public flaws in Zimbra, Telerik, AjaxPro and Alibaba Nacos to gain remote code execution at scale.
  • SPECTRE — first seen in April 2026 — is a cross-platform C backdoor with 45 Windows commands and 29 Linux commands, supporting credential theft, shell execution, process injection and anti-analysis checks.
  • On Windows, SPECTRE uses vulnerable MSI and Dell drivers to kill EDR visibility; on Linux, it can load the Specter kernel module, giving persistent root-level control that survives reboots.
  • Talos said the Chinese-speaking group also blends exfiltration into legitimate cloud and SaaS traffic, while reusing BadIIS malware tied to a malware-as-a-service ecosystem used by multiple Chinese-speaking cybercrime groups.

Insights

What makes the new cross-platform SPECTRE implant virtually invisible to top-tier security systems like CrowdStrike and Defender?
How is a cybercrime group using AI to silently turn thousands of global servers into untraceable SEO fraud machines?
Could your company's cloud administrative traffic actually be hiding massive data exfiltration orchestrated by AI-assisted hackers?

766 Hosts Compromised in 24 Hours: AI-Enabled Credential Harvesting, Attack Chain Automation, and the Global Response in 2026

Overview

In early 2026, cyber attackers rapidly exploited a critical Next.js vulnerability using automated scanning tools, compromising hundreds of global servers within a day. They deployed credential-harvesting scripts that stole sensitive data, including database and cloud credentials, by targeting both traditional and cloud-native environments. Meanwhile, other threat groups integrated AI-powered frameworks to automate attacks, making sophisticated intrusions easier and faster. Chinese-speaking groups shared malware to hijack websites for SEO fraud, damaging victims’ reputations and complicating attribution. As attackers moved at machine speed, traditional defenses became obsolete, pushing organizations to adopt AI-driven security, automated containment, and proactive exposure management to keep pace with evolving threats.

...