Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.

Daily Top · Nation-State

SPECTRE is UAT-10147's cross-platform implant — RTCore64, DBUtil, and a fake acpi_pad.ko

Talos 20 August 2026 — Chinese-speaking UAT-10147. SPECTRE does Windows BYOVD (MSI RTCore64 / Dell DBUtil) and a Linux rootkit as acpi_pad.ko. AI-shaped comments in recovered rootkit source. Web-server 1-days in, not a new 0-day class.

RWP Ventures · 2026-09-07 · event 2026-08-20 · 1 min read · priority 8.2

Bottom line up front

CONFIRMED 20 August 2026 Cisco Talos — UAT-10147, Chinese-speaking, hits Windows and Linux web servers globally (government, education, media, tech, gaming) using known web vulns, then SPECTRE. SPECTRE: cross-platform C2, injection, credential theft, anti-analysis. Windows: downloads RTCore64.sys (MSI, CVE-2019-16098) or DBUtil_2_3.sys (Dell, CVE-2021-21551) from C2, writes under %TEMP%, SCM service, IOCTL — classic BYOVD to strip EDR callbacks. Linux: Specter LKM disguised as acpi_pad.ko. Talos: recovered source suggests portions of the Linux rootkit may be AI-assisted. Companion post the same day: agentic-AI recon and payload generation after the foothold, SPECTRE preferred via certutil.

This is not speculative execution (the CPU bug). Do not confuse names. It is not ICS malware because a factory has a Linux historian.

What happened

1-day on the web server → root/SYSTEM → SPECTRE + optional Gh0stCringe/Meterpreter/NoodleRAT. BadIIS SEO fraud sits in the same actor's bag from earlier Talos work — monetization, not the SPECTRE story.

Why it matters

LOLDrivers has had both BYOVD families since 2023. If those drivers still load, EDR was a suggestion.

What is confirmed vs not

CONFIRMED Talos implant capabilities and driver pair.

ASSESSED AI-assisted rootkit (Talos “suggests”).

UNKNOWN named Fortune victims.

What defenders should do

  1. Block RTCore64.sys and DBUtil_2_3.sys by hash/cert (HVCI/WDAC).
  2. Alert on acpi_pad.ko that is not the distro package.
  3. Patch internet IIS/Apache/Nginx; this actor scales 1-days.

RWP assessment

Confidence: High on Talos TTPs. The AI angle is a development note, not the reason to patch.

Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.

Sources

  1. Cisco Talos — UAT-10147 deploys SPECTRE
  2. Cisco Talos — UAT-10147 agentic AI post-compromise (companion)
  3. LOLDrivers — RTCore64 / DBUtil (CVE-2019-16098, CVE-2021-21551)