Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.
SPECTRE is UAT-10147's cross-platform implant — RTCore64, DBUtil, and a fake acpi_pad.ko
Talos 20 August 2026 — Chinese-speaking UAT-10147. SPECTRE does Windows BYOVD (MSI RTCore64 / Dell DBUtil) and a Linux rootkit as acpi_pad.ko. AI-shaped comments in recovered rootkit source. Web-server 1-days in, not a new 0-day class.
Bottom line up front
CONFIRMED 20 August 2026 Cisco Talos — UAT-10147, Chinese-speaking, hits Windows and Linux web servers globally (government, education, media, tech, gaming) using known web vulns, then SPECTRE. SPECTRE: cross-platform C2, injection, credential theft, anti-analysis. Windows: downloads RTCore64.sys (MSI, CVE-2019-16098) or DBUtil_2_3.sys (Dell, CVE-2021-21551) from C2, writes under %TEMP%, SCM service, IOCTL — classic BYOVD to strip EDR callbacks. Linux: Specter LKM disguised as acpi_pad.ko. Talos: recovered source suggests portions of the Linux rootkit may be AI-assisted. Companion post the same day: agentic-AI recon and payload generation after the foothold, SPECTRE preferred via certutil.
This is not speculative execution (the CPU bug). Do not confuse names. It is not ICS malware because a factory has a Linux historian.
What happened
1-day on the web server → root/SYSTEM → SPECTRE + optional Gh0stCringe/Meterpreter/NoodleRAT. BadIIS SEO fraud sits in the same actor's bag from earlier Talos work — monetization, not the SPECTRE story.
Why it matters
LOLDrivers has had both BYOVD families since 2023. If those drivers still load, EDR was a suggestion.
What is confirmed vs not
CONFIRMED Talos implant capabilities and driver pair.
ASSESSED AI-assisted rootkit (Talos “suggests”).
UNKNOWN named Fortune victims.
What defenders should do
- Block RTCore64.sys and DBUtil_2_3.sys by hash/cert (HVCI/WDAC).
- Alert on
acpi_pad.kothat is not the distro package. - Patch internet IIS/Apache/Nginx; this actor scales 1-days.
RWP assessment
Confidence: High on Talos TTPs. The AI angle is a development note, not the reason to patch.
Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-20 and was added to the RWP archive on 2026-09-07.
Sources
- Cisco Talos — UAT-10147 deploys SPECTRE
- Cisco Talos — UAT-10147 agentic AI post-compromise (companion)
- LOLDrivers — RTCore64 / DBUtil (CVE-2019-16098, CVE-2021-21551)