UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Talos details SPECTRE, a cross-platform implant tied to UAT-10147 that combines Linux rootkit, BYOVD-based EDR bypass, and credential theft — raising the bar for endpoint detection on mixed-OS estates.
Summary written by editorial AI · Source link below
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
Editorial Analysis
A commodity implant offering kernel-level EDR bypass on both Windows and Linux forces security teams to validate detection coverage across the entire OS stack, not just Windows endpoints.
Validate that EDR solutions detect BYOVD driver loading on Windows and audit Linux hosts for kernel module integrity to counter rootkit-based evasion.
A new cross-platform hacking tool can bypass endpoint security on both Windows and Linux, requiring validation of detection capabilities across the server fleet.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Cisco Talos in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d