Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Driven Cyber Attacks Exploit Servers with SPECTRE Malware

AI-Driven Cyber Attacks Exploit Servers with SPECTRE Malware

Posted on August 24, 2026 By CWS

Cybersecurity experts have uncovered details about a Chinese-speaking cybercriminal group known as UAT-10147. This group is targeting Windows and Linux web servers worldwide, focusing on sectors such as education, media, technology, and gaming.

Geographical Targets and Tactics

UAT-10147 targets servers primarily in Brazil, Bolivia, China, Canada, and Vietnam. The group’s activities were traced back to a directory at “139.180.197[.]150,” which connected with compromised devices. According to Cisco Talos, they exploit known vulnerabilities for initial access, using tools like Metasploit and PentestGPT to automate their operations.

By leveraging artificial intelligence, UAT-10147 refines exploits and automates various phases of their attacks, from reconnaissance to persistence. This method allows them to implement offensive strategies on a large scale, making them a significant threat.

Exploiting Vulnerabilities with AI

An analysis revealed a list of approximately 170,000 URLs targeted by the attackers, divided into smaller subsets for efficiency. The most targeted regions include the U.S., India, the U.K., Germany, and the Netherlands. Their attack strategy involves exploiting security flaws to execute remote code and deploy malware for SEO fraud or data theft.

The group’s use of AI tools like DeepAudit for vulnerability scanning highlights their sophisticated approach. Although there is no evidence yet of vulnerabilities being exploited by this tool in victim environments, it suggests potential for future attacks or even defensive improvements.

Advanced Malware Deployments

Among the tools used by UAT-10147 is the SPECTRE implant, a cross-platform backdoor with advanced features like process injection and credential theft. This malware enables remote command-and-control operations while bypassing endpoint detection and response systems.

The Linux version of SPECTRE employs a kernel-level rootkit called Specter, developed using AI and human expertise. This rootkit maintains control over compromised hosts, surviving reboots and evading security measures, which poses a significant challenge for cybersecurity defenses.

The use of AI-driven techniques by UAT-10147 marks a new era in cyber warfare, blending technology with malware-as-a-service models. As these methods evolve, they underline the need for robust cybersecurity strategies to counteract such sophisticated threats.

The Hacker News Tags:AI cyber attacks, Cybercrime, Cybersecurity, data theft, deep audit, EDR bypass, Linux rootkit, SEO fraud, server exploits, SPECTRE malware, Threat Actors, UAT-10147, vulnerability scanning

Post navigation

Previous Post: AWS Enhances Network Firewall with Rule Hit Count Feature
Next Post: AI-Powered RedC2 Linux Implant via npm Packages Exposed

Related Posts

Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities The Hacker News
INC Ransomware Exploits SonicWall Vulnerabilities INC Ransomware Exploits SonicWall Vulnerabilities The Hacker News
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera The Hacker News
Rethinking AI Data Security: A Buyer’s Guide  Rethinking AI Data Security: A Buyer’s Guide  The Hacker News
ShinyHunters Exploit Oracle Zero-Day to Target Universities ShinyHunters Exploit Oracle Zero-Day to Target Universities The Hacker News
LiteSpeed Plugin Flaw Exploited for Root Access LiteSpeed Plugin Flaw Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hugging Face Considers $13 Billion Sale Amid AI Security Event
  • Iranian Cyberattack Disrupts UK Power Plant for Four Days
  • AI-Powered RedC2 Linux Implant via npm Packages Exposed
  • AI-Driven Cyber Attacks Exploit Servers with SPECTRE Malware
  • AWS Enhances Network Firewall with Rule Hit Count Feature

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hugging Face Considers $13 Billion Sale Amid AI Security Event
  • Iranian Cyberattack Disrupts UK Power Plant for Four Days
  • AI-Powered RedC2 Linux Implant via npm Packages Exposed
  • AI-Driven Cyber Attacks Exploit Servers with SPECTRE Malware
  • AWS Enhances Network Firewall with Rule Hit Count Feature

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark