SPECTRE is a custom cross-platform backdoor written in C, with separate Windows and Linux variants, used by the Chinese-speaking, financially motivated threat actor UAT-10147 since at least April 2026. It is deployed after compromise of internet-facing web servers, including Microsoft IIS and Linux systems, in campaigns exploiting publicly disclosed remote-code-execution vulnerabilities. Associated intrusions have affected government, education, media, technology, and gaming organizations, including victims in Brazil, Bolivia, China, Canada, and Vietnam.
SPECTRE communicates with command-and-control infrastructure using HTTP POST requests. Its Windows variant extends the Havoc framework and supports 45 commands covering reconnaissance, file operations and transfer, shell execution, screenshots, keylogging, credential theft, privilege escalation, process injection, and in-memory .NET assembly execution. Credential-access functions include collecting Windows credential stores and browser login data. Injection techniques include process hollowing, Early Bird APC injection, and self-hollowing. Named-pipe impersonation enables elevation to SYSTEM. Defense-evasion features include dynamically resolved APIs, encrypted strings, weighted anti-analysis checks, and configuration storage in NTFS alternate data streams. Its bring-your-own-vulnerable-driver capability abuses drivers associated with CVE-2019-16098 and CVE-2021-21551 to remove kernel notification callbacks and impair endpoint-security telemetry for the remainder of the compromised-system session.
The Linux variant is a statically linked x86-64 ELF implant supporting 29 commands, anti-sandbox checks, timestamp manipulation, and deployment and control of the separate Specter kernel rootkit. Specter provides boot persistence through a fraudulent systemd service, process and module concealment, and elevation to UID 0. It uses the Linux ftrace framework to redirect kernel handlers, enabling persistent kernel-level control and stealth. Both SPECTRE variants can terminate when their weighted anti-analysis checks indicate an analysis environment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SPECTRE can retrieve the vulnerable MSI RTCore64.sys driver associated with CVE-2019-16098, install it as a temporary kernel service, and abuse its kernel read/write capabilities to unlink registered EDR callbacks. | “SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
SPECTRE can retrieve Dell's DBUtil_2_3.sys driver associated with CVE-2021-21551, install it as a temporary kernel service, and abuse its kernel read/write capabilities to unlink registered EDR callbacks. | “SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“SPECTRE is a custom backdoor written in C with separate Windows and Linux variants.”
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
T1055.001 — Process Injection: Dynamic-link Library Injection (Defense Evasion)
45 commandes dont : injection de processus (hollowing, APC EarlyBird, self-hollowing sur RuntimeBroker.exe)
The Windows version is equipped to perform file operations ... inject shellcode, use process hollowing and Early Bird APC injection
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root | The BYOVD attack utilizes two well-known vulnerable drivers MSI's "RTCore64.sys" (CVE-2019-16098) and Dell's "DBUtil_2_3.sys" (CVE-2021-21551) to obtain elevated privileges and terminate security-related processes.
élévation de privilèges (named pipe impersonation → token SYSTEM)
SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
T1055.001 — Process Injection: Dynamic-link Library Injection (Defense Evasion)
45 commandes dont : injection de processus (hollowing, APC EarlyBird, self-hollowing sur RuntimeBroker.exe)
The Windows version is equipped to perform file operations ... inject shellcode, use process hollowing and Early Bird APC injection
Deleting initial payloads to cover its tracks and thwart forensic analysis
élévation de privilèges (named pipe impersonation → token SYSTEM)
Both versions employ a weighted scoring mechanism that causes the program to self-terminate if the score exceeds 50 points. The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
vol de credentials (SAM/SYSTEM/SECURITY hive dump, Chromedump, Vaultdump)
The Windows version is equipped to perform file operations, record keystrokes, take screenshots, download/upload files, execute shell commands, get running processes
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes
Both versions employ a weighted scoring mechanism that causes the program to self-terminate if the score exceeds 50 points. The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform Windows/Linux backdoor used by UAT-10147 for post-exploitation. It supports reconnaissance, file and shell operations, screenshots, credential theft, keylogging, process injection, privilege escalation, in-memory .NET execution, and HTTP POST C2. Its Windows variant includes anti-analysis capabilities and a BYOVD-based mechanism to disable EDR telemetry; its Linux variant can deploy the Specter kernel rootkit.
Custom-developed backdoor used by UAT-10147. The report says it supports cross-platform command-and-control operations, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass functionality.
A cross-platform implant used for post-exploitation that provides command-and-control, process injection, credential theft, anti-analysis features, and BYOVD-based EDR bypass.
A previously unreported cross-platform backdoor/implant used by UAT-10147 on Windows and Linux. It communicates over HTTPS with C2 infrastructure, supports extensive remote command execution and host control, includes anti-analysis and anti-sandbox checks, and on Windows supports keylogging, screenshots, shellcode injection, process hollowing, Early Bird APC injection, credential theft, and BYOVD-based EDR bypass. The Linux variant supports reconnaissance and shell execution and can deploy the Specter kernel rootkit for persistent kernel-level control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.