UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

A cybercrime group tracked as UAT-10147 is using artificial intelligence tools to help scale attacks against internet-facing servers, and is deploying a malware toolset called SPECTRE that includes endpoint detection and response (EDR) evasion capabilities and a Linux rootkit component, according to a report published by The Hacker News on August 24, 2026.

What the campaign involves

Reporting describes UAT-10147 as using AI-assisted techniques to accelerate reconnaissance and exploitation against server infrastructure, rather than relying solely on manual attack chains. Once inside a target environment, the group is reported to deploy SPECTRE, which combines capabilities to bypass or blind EDR tooling with a Linux-focused rootkit intended to maintain stealthy, persistent access.

Why it matters

The use of AI-assisted tooling to scale attacks against server infrastructure reflects a trend that both offensive and defensive researchers have flagged repeatedly through 2026: attackers are using automation and AI assistance to compress the time between reconnaissance and exploitation, while defenders increasingly rely on AI-assisted detection to keep pace. A rootkit paired with EDR-bypass capability is also a reminder that Linux server estates — often assumed to be lower-risk than Windows endpoints — remain a high-value target, particularly where detection tooling coverage is weaker than on the desktop fleet.

Sources

More coverage like this is available on Technology News.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *