An exposed directory held a target list of approximately 170,000 URLs — sliced into 17 files to make automated parsing more efficient — revealing a global campaign that Cisco Talos attributes to a Chinese‑speaking cybercrime group it calls UAT-10147.
UAT-10147's AI-assisted operations
Cisco Talos' two‑part report found the actor used a mixture of open‑source offensive frameworks — Metasploit, ysoserial, PentestGPT, DeepAudit and others — and layered AI tools into several phases of the attack lifecycle. Talos says the group employed AI to refine exploits, troubleshoot logic, automate post‑exploitation workflows, validate exploits and generate operational documentation, "indicating an attempt to implement offensive tradecraft at scale."
Talos also discovered DeepAudit, an AI‑driven vulnerability scanning framework, left accessible on the group's management server. The researchers found no evidence that DeepAudit had been used to exploit victims in the observed intrusions, but raised the possibility the tooling could either be aimed at identifying new targets or at hardening the actor's own infrastructure.
SPECTRE implant: cross‑platform C2 and EDR bypass
Talos identified a previously unreported cross‑platform backdoor called SPECTRE, a C‑written implant with anti‑analysis and obfuscation techniques that communicates with command‑and‑control (C2) over HTTPS. Talos traced the group's first use of SPECTRE to April 2026 and described it as "a significant evolution in commodity intrusion tooling," citing its integration of cross‑platform C2, process injection, credential theft, anti‑analysis protections and kernel‑level endpoint detection and response (EDR) bypass functionality.
The Windows build supports as many as 45 commands — file operations, keystroke recording, screenshots, shell execution, process hollowing, Early Bird APC injection and shellcode injection — and can "kill EDR processes using the bring your own vulnerable driver (BYOVD) technique," Talos said. The BYOVD approach leverages vulnerable drivers MSI's RTCore64.sys (CVE‑2019‑16098) and Dell's DBUtil_2_3.sys (CVE‑2021‑21551) to obtain elevated privileges and terminate security processes.
Talos explained the kernel‑level manipulation in blunt terms: "By performing targeted kernel writes, the SPECTRE safely unlinks each registered EDR callback from its doubly‑linked list," rendering callback‑dependent products such as CrowdStrike Falcon, SentinelOne and Microsoft Defender "completely blind to new process creations, thread creations, and image load events for the remainder of the session."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWindows attack chain: BadIIS, Quasar RAT and deceptive persistence
Talos describes the Windows intrusions as an automated chain: exploit a web application or vulnerable IIS server to gain remote code execution, then run scripts to download and deploy follow‑on implants for SEO fraud or data theft. The actor deployed web shells that led to BadIIS — a MaaS variant used by multiple Chinese‑speaking groups — and additional backdoors.
One observed sequence used certutil in a batch script to pull EfsPotato (a privilege‑escalation tool), a secondary batch script and Quasar RAT from adminapi.tippusoni[.]in. EfsPotato was used to escalate to SYSTEM and to configure Microsoft Defender exclusions; the group then deleted initial payloads to frustrate forensic analysis. The secondary script silently launched Quasar RAT and established persistence via a scheduled task named "Google Chrome Start." Follow‑on downloads installed BadIIS and other implants such as Gh0stCringe.
Linux intrusions: local privilege escalation and the Specter kernel rootkit
On Linux hosts, Talos observed widespread exploitation of known vulnerabilities for initial access followed by multiple LPE exploits to reach root, including CVE‑2022‑0995, CVE‑2021‑3156, CVE‑2015‑5287, CVE‑2015‑3246, CVE‑2010‑3904 and CVE‑2022‑0847. Once root access was achieved, the actor deployed backdoors including Noodle RAT, SPECTRE and Meterpreter to reach outbound C2.
Talos emphasized the Linux SPECTRE variant installs a kernel‑level rootkit named Specter as a kernel module. "This architecture grants the threat actor persistent, kernel‑level control of the compromised host that survives both reboots and most user‑level security controls," Talos said, noting the module aims to prevent detection from security products.
The Linux SPECTRE agent runs anti‑sandbox checks and uses a weighted scoring mechanism that self‑terminates if the score exceeds 50, examining process names, RAM, CPU cores, disk space, sleep acceleration and common sandbox hostnames and usernames.
What this means for technologists, procurement leaders, and cloud administrators
- Technologists and security teams: Expect automated exploitation at scale and sophisticated post‑exploitation that can neutralize endpoint visibility. Talos' finding that exfiltration was routed through a legitimate cloud configuration service underscores the need to correlate SaaS configuration traffic with other telemetry.
- Procurement leaders and defenders of web infrastructure: The campaign leverages commodity MaaS tools (BadIIS), publicly disclosed exploits and open‑source pentesting frameworks like PentestGPT. Buyers and operators should assume attackers can adapt freely from public proof‑of‑concepts and consider how quickly patching and vulnerability management processes can respond.
- Cloud administrators and SaaS operators: Talos noted the actor routed stolen data into a cloud‑based configuration management service (Alibaba Nacos), allowing asynchronous exfiltration and verification without maintaining persistent inbound shells. Cloud configuration and access audit trails should be treated as a potential exfiltration channel.
Talos' analysis paints UAT‑10147 as a campaign that combines old vulnerabilities and commodity malware with new, AI‑assisted orchestration and a kernel‑level persistence capability. The exposed 170,000‑URL list and the deployment of SPECTRE and Specter suggest a program built to scale, to evade detection, and to blend with legitimate cloud traffic — a combination that will demand defenders rethink both endpoint protections and the signals they trust.




