SPECTRE is a custom C-based cross-platform backdoor used by the Chinese-speaking, financially motivated intrusion actor UAT-10147 against internet-exposed Windows and Linux servers. Observed targeting includes government, education, media, technology, and gaming organizations. It is deployed after compromise as part of the actor’s post-exploitation toolkit.
Windows and Linux variants provide HTTP-based command-and-control, host reconnaissance, file operations, shell execution, anti-analysis, and command-driven post-exploitation. The Windows variant supports screenshots, keylogging, credential theft from Windows credential stores and browser data, registry-hive dumping, named-pipe impersonation for SYSTEM-level privileges, in-memory .NET assembly execution, and process-injection methods including process hollowing and Early Bird APC injection. It dynamically resolves APIs and encrypts embedded strings, and uses weighted sandbox and analysis-environment checks that can terminate execution when a threshold is reached.
The Windows variant also includes a bring-your-own-vulnerable-driver capability using drivers associated with CVE-2019-16098 and CVE-2021-21551. This capability obtains kernel memory access to remove Windows kernel notification callbacks, impairing telemetry from callback-dependent endpoint security products for the remainder of the compromised-system session. The Linux variant is a statically linked x86-64 ELF implant with analogous anti-sandbox behavior and can deploy the Specter Linux kernel rootkit. Specter provides boot-persistent kernel-level control, process and module hiding, and privilege escalation through ftrace-based syscall-handler redirection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SPECTRE can retrieve the vulnerable MSI RTCore64.sys driver associated with CVE-2019-16098, install it as a temporary kernel service, and abuse its kernel read/write capabilities to unlink registered EDR callbacks. | “SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
SPECTRE can retrieve Dell's DBUtil_2_3.sys driver associated with CVE-2021-21551, install it as a temporary kernel service, and abuse its kernel read/write capabilities to unlink registered EDR callbacks. | “SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
T1055.001 — Process Injection: Dynamic-link Library Injection (Defense Evasion)
45 commandes dont : injection de processus (hollowing, APC EarlyBird, self-hollowing sur RuntimeBroker.exe)
The Windows version is equipped to perform file operations ... inject shellcode, use process hollowing and Early Bird APC injection
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root | The BYOVD attack utilizes two well-known vulnerable drivers MSI's "RTCore64.sys" (CVE-2019-16098) and Dell's "DBUtil_2_3.sys" (CVE-2021-21551) to obtain elevated privileges and terminate security-related processes.
élévation de privilèges (named pipe impersonation → token SYSTEM)
SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
T1055.001 — Process Injection: Dynamic-link Library Injection (Defense Evasion)
45 commandes dont : injection de processus (hollowing, APC EarlyBird, self-hollowing sur RuntimeBroker.exe)
The Windows version is equipped to perform file operations ... inject shellcode, use process hollowing and Early Bird APC injection
Deleting initial payloads to cover its tracks and thwart forensic analysis
élévation de privilèges (named pipe impersonation → token SYSTEM)
Both versions employ a weighted scoring mechanism that causes the program to self-terminate if the score exceeds 50 points. The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
vol de credentials (SAM/SYSTEM/SECURITY hive dump, Chromedump, Vaultdump)
The Windows version is equipped to perform file operations, record keystrokes, take screenshots, download/upload files, execute shell commands, get running processes
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes
Both versions employ a weighted scoring mechanism that causes the program to self-terminate if the score exceeds 50 points. The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform Windows/Linux backdoor used by UAT-10147 for post-exploitation. It supports reconnaissance, file and shell operations, screenshots, credential theft, keylogging, process injection, privilege escalation, in-memory .NET execution, and HTTP POST C2. Its Windows variant includes anti-analysis capabilities and a BYOVD-based mechanism to disable EDR telemetry; its Linux variant can deploy the Specter kernel rootkit.
Custom-developed backdoor used by UAT-10147. The report says it supports cross-platform command-and-control operations, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass functionality.
A cross-platform implant used for post-exploitation that provides command-and-control, process injection, credential theft, anti-analysis features, and BYOVD-based EDR bypass.
A previously unreported cross-platform backdoor/implant used by UAT-10147 on Windows and Linux. It communicates over HTTPS with C2 infrastructure, supports extensive remote command execution and host control, includes anti-analysis and anti-sandbox checks, and on Windows supports keylogging, screenshots, shellcode injection, process hollowing, Early Bird APC injection, credential theft, and BYOVD-based EDR bypass. The Linux variant supports reconnaissance and shell execution and can deploy the Specter kernel rootkit for persistent kernel-level control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.