# Researchers detail UAT-10147 server campaign and SPECTRE implant

_Monday, August 24, 2026 at 4:08 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers detail UAT-10147 server campaign and SPECTRE implant — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4-mx98ENuq77sCTBd49TSl4Ov5dD1Wua0Vf1MiyVVPfcFckY__TjnTEOeC5CIQWX4L_OLA-xZHHY5nAlp926SIpa3eK8Tvfw1HSHHK1GMot7noTz4Cg36t-ZuZ-NUh5mnsfzs0HJ8F7p410LgWFVPN39PYh8YR6qkDlE8duNKmKpOtJHW4NA9T_ddTGLp/s1700-e365/hackers.jpg)

Cybersecurity researchers said Chinese-speaking group UAT-10147 is targeting Windows and Linux web servers in education, media, technology and gaming, using publicly disclosed vulnerabilities and automated tools.

Cisco Talos, cited by The Hacker News, said its analysis found a target list of about 170,000 URLs and a previously unreported cross-platform implant, SPECTRE. The reported Windows tool can use vulnerable drivers to disable endpoint-detection processes; the Linux version can load a kernel rootkit.

Talos said it found no evidence that the group had exploited vulnerabilities discovered by DeepAudit in victim environments.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html)

---
Canonical: https://techandbusiness.org/newswire/R7dtQLKJlDbzIKAWQXMstt
Retrieved: 2026-08-24T12:04:47.424Z
Publisher: Tech & Business (techandbusiness.org)
