A cybercrime group tracked as UAT-10147 is using artificial intelligence tools to help scale attacks against internet-facing servers, and is deploying a malware toolset called SPECTRE that includes endpoint detection and response (EDR) evasion capabilities and a Linux rootkit component, according to a report published by The Hacker News on August 24, 2026.
What the campaign involves
Reporting describes UAT-10147 as using AI-assisted techniques to accelerate reconnaissance and exploitation against server infrastructure, rather than relying solely on manual attack chains. Once inside a target environment, the group is reported to deploy SPECTRE, which combines capabilities to bypass or blind EDR tooling with a Linux-focused rootkit intended to maintain stealthy, persistent access.
Why it matters
The use of AI-assisted tooling to scale attacks against server infrastructure reflects a trend that both offensive and defensive researchers have flagged repeatedly through 2026: attackers are using automation and AI assistance to compress the time between reconnaissance and exploitation, while defenders increasingly rely on AI-assisted detection to keep pace. A rootkit paired with EDR-bypass capability is also a reminder that Linux server estates — often assumed to be lower-risk than Windows endpoints — remain a high-value target, particularly where detection tooling coverage is weaker than on the desktop fleet.
Sources
More coverage like this is available on Technology News.
