INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Exploits and Vulnerabilities in Q2 2026
| 2026-08-26 10:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Langflow vulnerability is a critical AI technology exploitation case that requires modern enterprise-grade security solutions to detect and prevent. It involves exploiting local privilege escalation vulnerabilities in Windows Defender, which can lead to initial access and privilege escalation. The attackers use NTFS Streams to circumvent controls on directory contents, making it difficult to track the overall health of systems and workstations. This vulnerability has been assigned a CVE identifier: BlueHammer : a local privilege escalation vulnerability in Windows Defender. Other vulnerabilities listed include CVE-2026-31431 (Copy Fail) and CVE-2026-43284 (Dirty Frag), which can be leveraged to gain initial access and escalate privileges, as well as CVE-2023-46604 (insecure deserialization vulnerability in Apache ActiveMQ). These exploits have the potential to compromise cloud and containerized environments.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested. However, please note that the articles provided are from 2026 and do not have a release date yet. I'll base my response on general security best practices and mitigation strategies.
General Security Best Practices:
* Regularly update and patch operating systems, applications, and firmware to prevent exploitation of known vulnerabilities.
* Use strong passwords, enable multi-factor authentication (MFA), and keep software up-to-date.
* Implement a web application firewall (WAF) and configure it to block common attacks.
* Monitor system logs for suspicious activity and respond quickly to potential threats.
Mitigation Strategies:
* Implement AI-powered security controls that analyze vast amounts of data to identify potential vulnerabilities and anomalies.
* Use machine learning-based intrusion detection systems to detect and prevent advanced persistent threats (APTs).
* Employ behavioral analysis to detect and block suspicious user behavior, such as login attempts from unknown locations or devices.
* Utilize threat intelligence feeds to stay informed about emerging threats and update security controls accordingly.
Network Security:
* Implement robust network segmentation to isolate sensitive data and systems.
* Use firewalls with advanced features like intrusion prevention and sandboxing.
* Configure network access control (NAC) to restrict access to authorized devices and users.
* Regularly scan networks for vulnerabilities and perform vulnerability assessments.
Endpoint Security:
* Install and regularly update antivirus software on all endpoints, including desktops, laptops, and mobile devices.
* Use a host-based intrusion detection system (HIDS) to monitor endpoint activity.
* Implement a virtual private network (VPN) to encrypt data in transit.
* Regularly back up critical data to prevent loss in case of an attack.
Cloud Security:
* Implement cloud security controls like identity and access management (IAM), encryption, and secure storage.
* Use cloud-based threat intelligence feeds to stay informed about emerging threats.
* Configure cloud-based intrusion detection systems to detect and prevent attacks on cloud infrastructure.
* Regularly scan clouds for vulnerabilities and perform vulnerability assessments.
Endpoint Protection:
* Install and regularly update endpoint security software like anti-malware, anti-ransomware, and anti-virus.
* Use a sandboxing environment to test and analyze suspicious files and activity.
* Implement a secure boot mechanism to ensure the integrity of operating systems and applications.
* Regularly patch and update all endpoints with the latest security patches.
Please note that these are general recommendations and not specific to the Q2 2026 vulnerability landscape. The best way to stay informed about emerging threats is to follow reputable sources and stay up-to-date on the latest security news and research.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.pdb
wi•••••.loader
rt•••••.sys
uc•••••.rs
nt•••••.exe
Ru•••••.exe
sv•••••.exe
cm•••••.exe
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign IDCampaign ID
EquationEquation
HavocHavoc
CVE-2015-5287CVE-2015-5287
CVE-2022-27925CVE-2022-27925
CVE-2026-46300CVE-2026-46300
CVE-2026-45386CVE-2026-45386
CVE-2015-3246CVE-2015-3246
CVE-2019-13272CVE-2019-13272
CVE-2024-12356CVE-2024-12356
CVE-2026-43494CVE-2026-43494
CVE-2025-8088CVE-2025-8088
CVE-2023-32233CVE-2023-32233
CVE-2021-23758CVE-2021-23758
CVE-2021-22555CVE-2021-22555
CVE-2023-38831CVE-2023-38831
CVE-2025-53770CVE-2025-53770
CVE-2021-29441CVE-2021-29441
CVE-2026-31431CVE-2026-31431
CVE-2017-11882CVE-2017-11882
CVE-2026-25253CVE-2026-25253
CVE-2021-21551CVE-2021-21551
CVE-2019-18935CVE-2019-18935
CVE-2026-1731CVE-2026-1731
CVE-2023-36884CVE-2023-36884
CVE-2026-35273CVE-2026-35273
CVE-2022-0995CVE-2022-0995
CVE-2021-3156CVE-2021-3156
CVE-2026-41948CVE-2026-41948
CVE-2026-43284CVE-2026-43284
CVE-2026-45501CVE-2026-45501
CVE-2023-46604CVE-2023-46604
CVE-2022-0847CVE-2022-0847
CVE-2026-43500CVE-2026-43500
CVE-2026-31635CVE-2026-31635
CVE-2025-6218CVE-2025-6218
CVE-2026-46331CVE-2026-46331
CVE-2019-16098CVE-2019-16098
CVE-2010-3904CVE-2010-3904
CVE-2018-0802CVE-2018-0802
CVE-2017-0199CVE-2017-0199
CVE-2021-29442CVE-2021-29442
Target & Sectors
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
educationeducation
mediamedia
technologytechnology
Incident Timeline
Q1 2025
The number of Windows users who encountered exploits declined slightly compared to Q1 2025.
Click on any entity below to view its context and source!
tactic
Privilege Escalation
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
infrastructure
Linux
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
The number of users who encountered exploits in Q1 2025 is taken as 100% (
download
)
In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1.
vulnerability
CVE-2022-0847
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
vulnerability
CVE-2019-13272
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
vulnerability
CVE-2021-22555
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
organisation
CVE-2023-32233
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
general_metric
32233 CVE-2023
At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well:
CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications
CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation
CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem
CVE-2023-32233: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
infrastructure
Windows
Dynamics of the number of Windows users encountering exploits, Q1 2025 – Q2 2026.
general_metric
100 %
the start of 2025
Threat actors used a vulnerability in AI tool implementations to target and scale server attacks.
Click on any entity below to view its context and source!
organisation
CWE
It’s also worth looking at how AI tool vulnerabilities break down by type, according to the CWE system:
TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026
Interestingly, vulnerabilities of an undetermined type have ranked first in every quarter since the start of 2025.
organisation
AI/LLM
It’s also worth looking at how AI tool vulnerabilities break down by type, according to the CWE system:
TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026
Interestingly, vulnerabilities of an undetermined type have ranked first in every quarter since the start of 2025.
general_metric
6 TOP vulnerability types
It’s also worth looking at how AI tool vulnerabilities break down by type, according to the CWE system:
TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026
Interestingly, vulnerabilities of an undetermined type have ranked first in every quarter since the start of 2025.
Q1 2026
Threat actors used a publicly available AI-based exploit to scale server attacks targeting the Unmanned Aviation Technology (UAT) platform.
Q2 2026
Linux and Windows platforms were exploited in Q2 2026, with Linux being hit by a rough patch.
Click on any entity below to view its context and source!
infrastructure
Linux
The number of users who encountered exploits in Q1 2025 is taken as 100% (
download
)
In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1.
Windows and Linux vulnerability exploitation
Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches.
Linux also hit a rough patch in Q2 2026.
All the vulnerabilities published in Q2 2026 were, in one way or another, related to the Linux caching subsystem.
general_metric
100 %
The number of users who encountered exploits in Q1 2025 is taken as 100% (
download
)
In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1.
infrastructure
Windows
Windows and Linux vulnerability exploitation
Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches.
tactic
T1588.005 - Exploits
Exploits and vulnerabilities in Q2 2026.
organisation
APT
Vulnerability exploitation in APT attacks
We analyzed which vulnerabilities were exploited in APT attacks during Q2 2026.
April 2026
The threat actor used a previously unknown exploit to implant malware on the target server in April 2026.
2026/08/17
Threat actors used publicly disclosed AI vulnerabilities to scale server attacks.
2026/08/26
The attackers used a rootkit called GodPotato-10019688-1 to target IIS servers and exploit vulnerabilities in AI directories.
Click on any entity below to view its context and source!
organisation
Kaspersky
The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA).
organisation
CVE
The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA).
organisation
BDU
The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA).
organisation
GHSA
The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA).
infrastructure
Windows
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
At the time the technical details were published, none of the vulnerabilities had been assigned a CVE identifier:
BlueHammer
: a local privilege escalation vulnerability in Windows Defender.
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
A case in point: a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new “named” vulnerabilities across various Windows subsystems.
RedSun
: another logical vulnerability in Windows Defender with a working exploit.
The exploit incorporates fragments of algorithms that make it possible to leverage various logical vulnerabilities in Windows, effectively combining a large number of popular exploitation techniques.
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
RougePlanet
: yet another Windows Defender vulnerability that, like BlueHammer, stems from a TOCTOU issue, this time in the engine responsible for real-time system scanning.
UnDefend
: another vulnerability in the Windows Defender service.
Veteran vulnerabilities in Windows software also remain relevant.
That said, the number of Windows users who encountered exploits declined slightly in Q2, hitting an 18-month low.
The Windows version is equipped to perform file operations, record keystrokes, take screenshots, download/upload files, execute shell commands, get running processes, terminate a specific process, get system information, set beacon sleep interval, modify file timestamps, inject shellcode, use process hollowing and Early Bird APC injection, kill EDR processes using the bring your own vulnerable driver (BYOVD) technique, delete itself from the host.
Windows version
The Windows variant of SPECTRE distinguishes itself from the stock Havoc framework through custom post-exploitation and defense evasion capabilities compiled directly into the binary.
Windows version of SPECTRE.
Windows anti-sandbox scoring.
Additionally, Talos observed a specific version of the implant attempting to read its C2 configuration from an NTFS Alternate Data Stream (ADS) located at “C:\Windows\System32\drivers\etc\hosts:cache”.
Windows version command list.
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via SharpChrome
BYOVD EDR killer
SPECTRE downloads one of two well-known vulnerable driver from the C2 — either RTCore64.sys from MSI (associated with
CVE-2019-16098
) or DBUtil_2_3.sys from Dell (associated with
CVE-2021-21551
).
It then references a hardcoded, per-build offset table covering 13 Windows versions to calculate the exact kernel virtual addresses for PspCreateProcessNotifyRoutine, PspCreateThreadNotifyRoutine, and PspLoadImageNotifyRoutine.
Linux version
The SPECTRE Linux variant’s structure is the same as the Windows variant.
Following successful anti-sandbox validation, SPECTRE beacons to its hardcoded C2 domain with a JSON payload, which is the same as the Windows version.
Rather than 45 commands in the Windows variant, the Linux version of SPECTRE only has 29 commands, none of which result in obfuscation or encryption.
infrastructure
Linux
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
Here are the ones being most actively exploited:
CVE-2026-31431 (Copy Fail)
: a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges.
Especially dangerous for cloud and containerized environments
CVE-2026-43284, CVE-2026-43500 (Dirty Frag)
: a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root
CVE-2026-46300 (Fragnesia)
: a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
Linux version
The SPECTRE Linux variant’s structure is the same as the Windows variant.
Rather than 45 commands in the Windows variant, the Linux version of SPECTRE only has 29 commands, none of which result in obfuscation or encryption.
This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.
In particular, AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.
It lets an unprivileged user gain root privileges and is also classified as part of the Dirty Frag family
CVE-2026-31635 (DirtyDecrypt)
: a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations and page cache data modification
CVE-2026-43494 (PinTheft)
: a Linux kernel vulnerability that lets a local user gain elevated privileges due to errors in the memory page pinning mechanism
CVE-2026-46331 (pedit COW)
: a vulnerability in the Linux kernel’s traffic control subsystem (tc-pedit) that exploits a flaw in copy-on-write to modify the page cache and subsequently escalate privileges to root
The vulnerabilities described above were quickly embraced by attackers.
The Linux version's instruction set, in contrast, only supports 29 commands that encompass file system manipulation, system and process reconnaissance, agent management, and unrestricted shell execution.
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.
In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.
"Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine."
SPECTRE's Linux variant follows more or less the same pattern, running a series of anti-sandbox checks before setting up a C2 connection.
"The Spectre backdoor loads the Linux Kernel rootkit, Specter, to prevent detection from security products."
UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques.
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities.
The actor demonstrates operational maturity through the combined use of custom malware, open-source offensive tooling, Bring Your Own Virtual Driver (BYOVD) based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.
Cisco Talos’ analysis of recovered source code suggests portions of the Linux rootkit development may have incorporated AI-assisted code generation workflows, highlighting the growing role of generative AI in accelerating offensive malware development.
In our
previous blog
, Cisco Talos documented how UAT-10147 operationalized AI-assisted exploitation workflows to compromise internet-facing IIS and Linux servers at scale.
Linux version of SPECTRE.
It is a statically-linked ELF x86-64 binary targeting Linux systems.
Linux anti-sandbox scoring.
Linux hardcoded C2.
Linux version command list.
Specter Linux rootkit
The SPECTRE backdoor loads the Linux Kernel rootkit, Specter, to prevent detection from security products.
Based on the SPECTRE Linux version we observed, the compiled artifact is deployed disguised as “acpi_pad.ko”.
Rather than patching the syscall table, the hook mechanism rootkit uses the Linux kernel's native “ftrace” instrumentation framework with “FTRACE_OPS_FL_IPMODIFY” to redirect execution at the function entry point of six syscall handlers:
hooked_tcp6_seq_show
hooked_tcp4_seq_show
hooked_tkill
hooked_tgkill
hooked_kill
hooked_getdents64
Because “ftrace” is a legitimate kernel debugging interface, this approach produces minimal noise in kernel integrity checks.
Meterpreter
Talos has observed UAT-10147 deploying reverse Meterpreter shells to maintain persistent access to compromised Linux hosts.
Noodle RAT
UAT-10147 also deployed Noodle RAT against targeted Linux servers, utilizing it as a final stage backdoor to ensure persistent access.
Backdoor command for Linux Noodle RAT.
organisation
BlueHammer
At the time the technical details were published, none of the vulnerabilities had been assigned a CVE identifier:
BlueHammer
: a local privilege escalation vulnerability in Windows Defender.
organisation
CVE-2026-31431
Here are the ones being most actively exploited:
CVE-2026-31431 (Copy Fail)
: a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges.
organisation
Copy Fail
Here are the ones being most actively exploited:
CVE-2026-31431 (Copy Fail)
: a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges.
organisation
CVE-2026-43500
Especially dangerous for cloud and containerized environments
CVE-2026-43284, CVE-2026-43500 (Dirty Frag)
: a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root
CVE-2026-46300 (Fragnesia)
: a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism.
organisation
IPsec
Especially dangerous for cloud and containerized environments
CVE-2026-43284, CVE-2026-43500 (Dirty Frag)
: a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root
CVE-2026-46300 (Fragnesia)
: a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism.
organisation
RxRPC
Especially dangerous for cloud and containerized environments
CVE-2026-43284, CVE-2026-43500 (Dirty Frag)
: a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root
CVE-2026-46300 (Fragnesia)
: a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism.
organisation
CVE-2023-46604
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
organisation
CVE-2023-36884
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
infrastructure
Winrar
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2026
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
organisation
BeyondTrust
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
organisation
MoTW
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
organisation
Microsoft SharePoint
The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps
CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process
CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user
These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent.
organisation
DeepAudit
The actor employed a mixture of open-source offensive frameworks, including
Metasploit
,
ysoserial
,
PentestGPT
, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence.
organisation
EfsPotato
Some of the other steps undertaken by UAT-10147 is as follows -
Using a batch script that employs certutil to download a privilege escalation tool ("EfsPotato"), a secondary batch script, and Quasar RAT from a remote server ("adminapi.tippusoni[.]in")
While some of these tools, such as
GodPotato
and
JuicyPotato
, were downloaded as pre compiled binaries from the internet, others, like EfsPotato and RustPotato, were compiled by the threat actor directly from source code.
organisation
CVE-2022-0995
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
organisation
Local Privilege Escalation
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
organisation
LPE
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
organisation
CVE-2015
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
organisation
CVE-2022
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,
CVE-2015-5287
,
CVE-2015-3246
,
CVE-2010-3904
, and
CVE-2022-0847
.
organisation
Nightmare
A case in point: a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new “named” vulnerabilities across various Windows subsystems.
organisation
RedSun
RedSun
: another logical vulnerability in Windows Defender with a working exploit.
organisation
YellowKey
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
organisation
BitLocker
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
organisation
the Windows Recovery Environment
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
organisation
WinRE
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
organisation
GreenPlasma
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
organisation
CTF
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
organisation
the Collaborative Translation Framework
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
organisation
CTFMON
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
organisation
RougePlanet
RougePlanet
: yet another Windows Defender vulnerability that, like BlueHammer, stems from a TOCTOU issue, this time in the engine responsible for real-time system scanning.
organisation
NTFS Alternate Data Stream
Additionally, Talos observed a specific version of the implant attempting to read its C2 configuration from an NTFS Alternate Data Stream (ADS) located at “C:\Windows\System32\drivers\etc\hosts:cache”.
organisation
ADS
Additionally, Talos observed a specific version of the implant attempting to read its C2 configuration from an NTFS Alternate Data Stream (ADS) located at “C:\Windows\System32\drivers\etc\hosts:cache”.
organisation
MSI
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via SharpChrome
BYOVD EDR killer
SPECTRE downloads one of two well-known vulnerable driver from the C2 — either RTCore64.sys from MSI (associated with
CVE-2019-16098
) or DBUtil_2_3.sys from Dell (associated with
CVE-2021-21551
).
The BYOVD attack utilizes two well-known vulnerable drivers MSI's "RTCore64.sys" (CVE-2019-16098) and Dell's "DBUtil_2_3.sys" (CVE-2021-21551) to obtain elevated privileges and terminate security-related processes.
organisation
DPAPI
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via SharpChrome
BYOVD EDR killer
SPECTRE downloads one of two well-known vulnerable driver from the C2 — either RTCore64.sys from MSI (associated with
CVE-2019-16098
) or DBUtil_2_3.sys from Dell (associated with
CVE-2021-21551
).
organisation
SharpChrome
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via SharpChrome
BYOVD EDR killer
SPECTRE downloads one of two well-known vulnerable driver from the C2 — either RTCore64.sys from MSI (associated with
CVE-2019-16098
) or DBUtil_2_3.sys from Dell (associated with
CVE-2021-21551
).
organisation
Dell
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via SharpChrome
BYOVD EDR killer
SPECTRE downloads one of two well-known vulnerable driver from the C2 — either RTCore64.sys from MSI (associated with
CVE-2019-16098
) or DBUtil_2_3.sys from Dell (associated with
CVE-2021-21551
).
organisation
PspCreateProcessNotifyRoutine
It then references a hardcoded, per-build offset table covering 13 Windows versions to calculate the exact kernel virtual addresses for PspCreateProcessNotifyRoutine, PspCreateThreadNotifyRoutine, and PspLoadImageNotifyRoutine.
organisation
Dirty Frag
In particular, AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.
organisation
PinTheft
It lets an unprivileged user gain root privileges and is also classified as part of the Dirty Frag family
CVE-2026-31635 (DirtyDecrypt)
: a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations and page cache data modification
CVE-2026-43494 (PinTheft)
: a Linux kernel vulnerability that lets a local user gain elevated privileges due to errors in the memory page pinning mechanism
CVE-2026-46331 (pedit COW)
: a vulnerability in the Linux kernel’s traffic control subsystem (tc-pedit) that exploits a flaw in copy-on-write to modify the page cache and subsequently escalate privileges to root
The vulnerabilities described above were quickly embraced by attackers.
organisation
COW
It lets an unprivileged user gain root privileges and is also classified as part of the Dirty Frag family
CVE-2026-31635 (DirtyDecrypt)
: a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations and page cache data modification
CVE-2026-43494 (PinTheft)
: a Linux kernel vulnerability that lets a local user gain elevated privileges due to errors in the memory page pinning mechanism
CVE-2026-46331 (pedit COW)
: a vulnerability in the Linux kernel’s traffic control subsystem (tc-pedit) that exploits a flaw in copy-on-write to modify the page cache and subsequently escalate privileges to root
The vulnerabilities described above were quickly embraced by attackers.
organisation
EDR Bypass
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.
organisation
SentinelOne
"Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine."
SPECTRE's Linux variant follows more or less the same pattern, running a series of anti-sandbox checks before setting up a C2 connection.
Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine.
organisation
Microsoft Defender
"Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine."
SPECTRE's Linux variant follows more or less the same pattern, running a series of anti-sandbox checks before setting up a C2 connection.
Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine.
organisation
SEO
UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques.
Attack chains involve exploiting known flaws to achieve remote code execution (RCE) on a website or a vulnerable IIS server, and then run an automated script to install and deploy malware for SEO fraud or data stealing.
organisation
BYOVD
The actor demonstrates operational maturity through the combined use of custom malware, open-source offensive tooling, Bring Your Own Virtual Driver (BYOVD) based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.
The BYOVD attack utilizes two well-known vulnerable drivers MSI's "RTCore64.sys" (CVE-2019-16098) and Dell's "DBUtil_2_3.sys" (CVE-2021-21551) to obtain elevated privileges and terminate security-related processes.
organisation
ELF
It is a statically-linked ELF x86-64 binary targeting Linux systems.
organisation
CVE-2025-6218
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2018-0802
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2017-11882
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2017-0199
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2023-38831
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
Microsoft Office
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
threat_actor
Equation
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
WordPad
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
ZDI-CAN-27198
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
CVE-2025
These are the ones our solutions most frequently detect exploits for:
CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution
CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218.
organisation
Microsoft
Although Microsoft categorizes the potential impact of exploiting this vulnerability as spoofing, flaws like this can lead to alteration of displayed content, imitation of trusted interfaces, actions on behalf of the user within an active session, and abuse of user trust.
Using EfsPotato to gain elevated system privileges, configure Microsoft Defender exclusions
Deleting initial payloads to cover its tracks and thwart forensic analysis
Deploying follow-on implants like
Gh0stCringe
and a previously unreported cross-platform implant dubbed SPECTRE
Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start"
Abusing the elevated privileges to download a third batch script, which then installs BadIIS
Interestingly, the core BadIIS malware is the same specific variant that's known to operate under a malware-as-a-service (MaaS) model and is used by multiple Chinese-speaking cybercrime groups.
organisation
View State
Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects -
Making use of the
badsecrets
library comprising publicly known or leaked
ASP.NET MachineKey configurations
, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook
Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell
Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()"
Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant.
organisation
MachineKey
Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects -
Making use of the
badsecrets
library comprising publicly known or leaked
ASP.NET MachineKey configurations
, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook
Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell
Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()"
Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant.
organisation
ASHX
Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects -
Making use of the
badsecrets
library comprising publicly known or leaked
ASP.NET MachineKey configurations
, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook
Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell
Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()"
Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant.
organisation
ViewState
Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects -
Making use of the
badsecrets
library comprising publicly known or leaked
ASP.NET MachineKey configurations
, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution
Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook
Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell
Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()"
Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant.
organisation
Sliver
Sliver, Havoc, AdaptixC2, and Metasploit remain the most widely used C2 frameworks.
organisation
Oracle PeopleSoft PeopleTools
After studying open sources and analyzing samples of malicious C2 agents that contained exploits, we determined that the following vulnerabilities were utilized in APT attacks involving the C2 frameworks mentioned above:
CVE-2026-35273: a vulnerability in Oracle PeopleSoft PeopleTools that security vendors classify as server-side request forgery (SSRF).
organisation
WebSocket
CVE-2026-25253: a gatewayUrl vulnerability in OpenClaw
The issue stems from the fact that the OpenClaw user interface trusts the value of the gatewayUrl parameter passed in the URL and automatically establishes a WebSocket connection to the specified address.
organisation
Microsoft Exchange
CVE-2026-45501: a vulnerability in Microsoft Exchange
The vulnerability stems from improper neutralization of user input when generating Exchange web pages.
organisation
OpenClaw
For example, OpenClaw, a popular AI project, ranked 12th among those with the highest number of vulnerabilities discovered and published in Q2, with over 200 CVEs registered during the reporting period.
organisation
Next
Next, we analyze the number of new critical vulnerabilities (CVSS > 9.0) over the same period.
organisation
TOCTOU
During signature database updates, a time-of-check to time-of-use (TOCTOU) race condition occurs, allowing an attacker to substitute the directory where temporary update files are written.
organisation
SharePoint
For instance, we’re once again seeing exploits targeting SharePoint.
organisation
Exchange
It’s worth noting that while several vulnerability write-ups for Exchange and SharePoint were published during the quarter, most turned out to be fake, AI-generated research.
organisation
CWE-284
CWE-284 is an example of this.
organisation
Improper
Looking at the most common classes, the key issues found in AI-related software can be summed up as follows:
Inadequate access control over critical system objects
Improper implementation of authentication and authorization mechanisms
Injections
It’s worth noting that injection-related vulnerabilities were relatively rare before AI agents took off (previously, they mostly affected web apps).
organisation
LLM
Since the above already covers several significant vulnerabilities published during the reporting period, this section consists mainly of LLM/AI tool vulnerabilities.
organisation
Conditions
Depending on the Dify configuration, the consequences can include:
Unauthorized access to internal service interfaces
Breach of isolation between workspaces
Exposure of internal service information
Conditions favorable to further attacks when combined with other vulnerabilities
The use of Dify in enterprise AI platforms is particularly risky, since internal services there tend to hold elevated privileges.
organisation
API
In vulnerable versions, however, before performing these actions, the API only checked for read access to the channel (a chat between a user or group and the AI) containing the message, not permission to modify its content.
First, API resolution is executed entirely at runtime via PEB hash walking, using a DJB2 variant algorithm.
organisation
PEB
First, API resolution is executed entirely at runtime via PEB hash walking, using a DJB2 variant algorithm.
organisation
Content Security Policy
It’s worth noting that issues like this are still relevant in modern software, given that mechanisms like Content Security Policy and various parsers were specifically created to help developers neutralize dangerous parts of user page content.
organisation
Kaspersky Next
Kaspersky Next
meets these requirements by combining proactive mechanisms with the ability to respond promptly to emerging threats.
organisation
GodPotato
While some of these tools, such as
GodPotato
and
JuicyPotato
, were downloaded as pre compiled binaries from the internet, others, like EfsPotato and RustPotato, were compiled by the threat actor directly from source code.
organisation
JuicyPotato
While some of these tools, such as
GodPotato
and
JuicyPotato
, were downloaded as pre compiled binaries from the internet, others, like EfsPotato and RustPotato, were compiled by the threat actor directly from source code.
organisation
RustPotato
While some of these tools, such as
GodPotato
and
JuicyPotato
, were downloaded as pre compiled binaries from the internet, others, like EfsPotato and RustPotato, were compiled by the threat actor directly from source code.
organisation
HTTPS
The final script is responsible for blending exfiltration traffic with legitimate software-as-a-service (SaaS) traffic over HTTPS and transmitting webfoot enumeration, IIS site inventory, and privilege assessment details to a webhook endpoint.
organisation
AjaxPro
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include
CVE-2022-27925
(Zimbra),
CVE-2021-23758
(AjaxPro),
CVE-2019-18935
(Telerik UI for ASP.NET AJAX),
CVE-2021-29441
, and
CVE-2021-29442
(Alibaba Nacos).
organisation
PentestGPT
UAT-10147 has also been found to install PentestGPT, an open-source autonomous pentesting framework, on their C2 server to scan web servers and execute relevant proof-of-concept exploits.
organisation
EDR
"The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality," Talos
said
.
The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
organisation
RAM
The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
SPECTRE has a feature to execute a weighted anti-analysis scoring routine that evaluates process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
organisation
CPU
The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
SPECTRE has a feature to execute a weighted anti-analysis scoring routine that evaluates process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.
data_breach
17 smaller files
An analysis of the exposed directory has identified a text file containing a target list with approximately 170,000 URLs, with the attacker splitting it into 17 smaller files containing about 10,000 URLs each to more efficiently parse the set.
organisation
Delete
Print/change working directory
Environment variables information
Set beacon sleep interval
Network interface information
Revert impersonation token
List current token privileges
Delete implant file on disk
Write REG_SZ or REG_DWORD value:
regset
<HKLM|HKCU>\path value data
organisation
PDB
The BadIIS samples used in this activity contain the following PDB paths:
C:\Users\Administrator\Desktop\2025-11-21 (x神订制全站劫持按浏览器语言跳转)\dll\Release\demo.pdb
C:\Users\Administrator\Desktop\2025-11-21 (x神订制全站劫持按浏览器语言跳转)\dll\x64\Release\demo.pdb
We also identified that the BadIIS installer embeds a service installer containing an additional PDB string referencing “x神”:
C:\Users\Administrator\Desktop\x神的自安装服务\svchost\x64\Release\service.pdb
Beyond these xshen-related development artifacts, other components in the campaign also contain references to “X.” The ASHX SEO engine configuration includes a string named “X-seo,” while the web shell uses an “X-ID” HTTP header to transmit a specific token.
organisation
DLL
[REG_DWORD]
DLL injection (default: svchost.exe)
Token theft from target PID
Spawn token with credentials
Process hollowing injection
Dump SAM/SYSTEM/SECURITY hives
Copy Chrome & Edge Login Data + Local State to
ld
/ls/
ed_ld
/
ed_ls
.
organisation
Token
[REG_DWORD]
DLL injection (default: svchost.exe)
Token theft from target PID
Spawn token with credentials
Process hollowing injection
Dump SAM/SYSTEM/SECURITY hives
Copy Chrome & Edge Login Data + Local State to
ld
/ls/
ed_ld
/
ed_ls
.
organisation
PID
[REG_DWORD]
DLL injection (default: svchost.exe)
Token theft from target PID
Spawn token with credentials
Process hollowing injection
Dump SAM/SYSTEM/SECURITY hives
Copy Chrome & Edge Login Data + Local State to
ld
/ls/
ed_ld
/
ed_ls
.
organisation
Copy Chrome & Edge Login Data + Local State
[REG_DWORD]
DLL injection (default: svchost.exe)
Token theft from target PID
Spawn token with credentials
Process hollowing injection
Dump SAM/SYSTEM/SECURITY hives
Copy Chrome & Edge Login Data + Local State to
ld
/ls/
ed_ld
/
ed_ls
.
organisation
HKLM\SAM\SAM
With SYSTEM privileges, three registry hives HKLM\SAM\SAM, HKLM\SYSTEM, and HKLM\SECURITY are saved to “%TEMP%” via RegSaveKeyA for offline NT hash extraction using Impact “secretsdump.py”.
organisation
HKLM\SECURITY
With SYSTEM privileges, three registry hives HKLM\SAM\SAM, HKLM\SYSTEM, and HKLM\SECURITY are saved to “%TEMP%” via RegSaveKeyA for offline NT hash extraction using Impact “secretsdump.py”.
infrastructure
1.2.1
C:\Users\iis\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\widestring-1.2.1\src\ucstring.rs
C:\Users\iis\Desktop\AI\EfsPotatoCpp\x64\Release\EfsPotato.pdb
C:\Users\Intel\Desktop\AI\EfsPotatoCPP\x64\Debug\EfsPotato.pdb
Other backdoors for persistence
UAT-10147 leveraged other multiple backdoors throughout this attack.
organisation
APC
The second is APC EarlyBird injection, which utilizes pre-allocated memory to deliver shellcode before the target thread can execute a single instruction.
organisation
SCM
It then decodes and writes the driver to disk under %TEMP%, installs it as a transient kernel service via the SCM, and opens an IOCTL handle to the device.
organisation
IOCTL
It then decodes and writes the driver to disk under %TEMP%, installs it as a transient kernel service via the SCM, and opens an IOCTL handle to the device.
organisation
IPC
The user level communicates with the loaded kernel module through a signal-based IPC mechanism, issuing
kill()
syscalls targeting a magic PID value of 0x7A69 (decimal 31337, a
well-known "elite" hacker cultural
) with specific real-time signal numbers encoding the desired operation:
organisation
Signal
Signal 36 hides the module itself from lsmod by unlinking THIS_MODULE from the kernel module linked list.
organisation
ASHX SEO
ASHX SEO engine
This SEO hijacking web handler silently takes over an IIS application's request pipeline via reflection.
organisation
SHandler
Finally, the loader instantiates and invokes
SHandler.
organisation
ProcessRequest
ProcessRequest
to manage all subsequent incoming requests.
organisation
Trend Micro
The specific payload observed in this campaign is the Type 0x03A2 ELF variant, which was previously documented in research published by
Trend Micro
.
organisation
ClamAV
The following ClamAV signatures detect and block this threat:
Win.
organisation
Generic-9883082
Generic-9883082-0
Win.
organisation
Backdoor-6678692
Backdoor-6678692-0
Win.
organisation
Ulise-10056576-0
Win
Ulise-10056576-0
Win.
organisation
SNORT®
Badiis-10060290-1
The following SNORT® rules (SIDs) detect and block this threat:
Snort2: 1:66690, 1:66688, 1:66689
Snort3:
financial
0 Generic-10060218
Generic-10060218-0
Win.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
At the time the technical details were published, none of the vulnerabilities had been assigned a CVE identifier:
BlueHammer
: a local privilege escalation vulnerability in Windows Defender.
…at allow an attacker to send malicious commands even without system authentication
CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism
CVE-…
Windows and Linux vulnerability exploitation
Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches.
A case in point: a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new “named” vulnerabilities across various Windows subsystems.
RedSun
: another logical vulnerability in Windows Defender with a working exploit.
The exploit incorporates fragments of algorithms that make it possible to leverage various logical vulnerabilities in Windows, effectively combining a large number of popular exploitation techniques.
YellowKey
: a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE).
GreenPlasma
: a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows.
RougePlanet
: yet another Windows Defender vulnerability that, like BlueHammer, stems from a TOCTOU issue, this time in the engine responsible for real-time system scanning.
UnDefend
: another vulnerability in the Windows Defender service.
Veteran vulnerabilities in Windows software also remain relevant.
That said, the number of Windows users who encountered exploits declined slightly in Q2, hitting an 18-month low.
Dynamics of the number of Windows users encountering exploits, Q1 2025 – Q2 2026.
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
The Windows version is equipped to perform file operations, record keystrokes, take screenshots, download/upload files, execute shell commands, get running processes, terminate a specific process, get system information, set beacon sleep interval,…
Windows version
The Windows variant of SPECTRE distinguishes itself from the stock Havoc framework through custom post-exploitation and defense evasion capabilities compiled directly into the binary.
Windows version of SPECTRE.
Windows anti-sandbox scoring.
Additionally, Talos observed a specific version of the implant attempting to read its C2 configuration from an NTFS Alternate Data Stream (ADS) located at “C:\Windows\System32\drivers\etc\hosts:cache”.
Windows version command list.
Vaultdump:
Spawns
cmdkey.exe /list
with stdout capture to enumerate Windows Credential Manager entries without any LSASS access
Chromedump:
Copies Chrome and Edge login data and local state files to “%TEMP%” for offline DPAPI decryption via Sh…
It then references a hardcoded, per-build offset table covering 13 Windows versions to calculate the exact kernel virtual addresses for PspCreateProcessNotifyRoutine, PspCreateThreadNotifyRoutine, and PspLoadImageNotifyRoutine.
Linux version
The SPECTRE Linux variant’s structure is the same as the Windows variant.
Following successful anti-sandbox validation, SPECTRE beacons to its hardcoded C2 domain with a JSON payload, which is the same as the Windows version.
Rather than 45 commands in the Windows variant, the Linux version of SPECTRE only has 29 commands, none of which result in obfuscation or encryption.
Metrics
infrastructure
Linux
Affected Product
Here are the ones being most actively exploited:
CVE-2026-31431 (Copy Fail)
: a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges.
…for cloud and containerized environments
CVE-2026-43284, CVE-2026-43500 (Dirty Frag)
: a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to…
…33: another Netfilter subsystem vulnerability that allows for
Use-After-Free
conditions and privilege escalation through improper processing of network requests
Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026.
This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.
In particular, AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.
Windows and Linux vulnerability exploitation
Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches.
Linux also hit a rough patch in Q2 2026.
All the vulnerabilities published in Q2 2026 were, in one way or another, related to the Linux caching subsystem.
…leged user gain root privileges and is also classified as part of the Dirty Frag family
CVE-2026-31635 (DirtyDecrypt)
: a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations…
The number of users who encountered exploits in Q1 2025 is taken as 100% (
download
)
In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1.
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including
CVE-2022-0995
,
CVE-2021-3156
,…
The Linux version's instruction set, in contrast, only supports 29 commands that encompass file system manipulation, system and process reconnaissance, agent management, and unrestricted shell execution.
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.
In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.
…load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine."
SPECTRE's Linux variant follows more or less the same pattern, running a series of anti-sandbox checks before setting up a C2 connecti…
"The Spectre backdoor loads the Linux Kernel rootkit, Specter, to prevent detection from security products."
…a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion t…
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities.
…ates operational maturity through the combined use of custom malware, open-source offensive tooling, Bring Your Own Virtual Driver (BYOVD) based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.
Cisco Talos’ analysis of recovered source code suggests portions of the Linux rootkit development may have incorporated AI-assisted code generation workflows, highlighting the growing role of generative AI in accelerating offensive malware developm…
In our
previous blog
, Cisco Talos documented how UAT-10147 operationalized AI-assisted exploitation workflows to compromise internet-facing IIS and Linux servers at scale.
Linux version of SPECTRE.
Linux version
The SPECTRE Linux variant’s structure is the same as the Windows variant.
It is a statically-linked ELF x86-64 binary targeting Linux systems.
Linux anti-sandbox scoring.
Linux hardcoded C2.
Rather than 45 commands in the Windows variant, the Linux version of SPECTRE only has 29 commands, none of which result in obfuscation or encryption.
Linux version command list.
Specter Linux rootkit
The SPECTRE backdoor loads the Linux Kernel rootkit, Specter, to prevent detection from security products.
Based on the SPECTRE Linux version we observed, the compiled artifact is deployed disguised as “acpi_pad.ko”.
Rather than patching the syscall table, the hook mechanism rootkit uses the Linux kernel's native “ftrace” instrumentation framework with “FTRACE_OPS_FL_IPMODIFY” to redirect execution at the function entry point of six syscall handlers:
hooked_tc…
Meterpreter
Talos has observed UAT-10147 deploying reverse Meterpreter shells to maintain persistent access to compromised Linux hosts.
Noodle RAT
UAT-10147 also deployed Noodle RAT against targeted Linux servers, utilizing it as a final stage backdoor to ensure persistent access.
Backdoor command for Linux Noodle RAT.
Metrics
infrastructure
Winrar
Affected Product
…enticated command execution on the server
CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility d…
…n Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive
CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR…
Metrics
infrastructure
Microsoft Office
Affected Product
…or component
CVE-2017-11882: another RCE vulnerability also affecting Equation Editor
CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system
CVE-2023-38831: a vulnerability in Wi…
Metrics
data_breach
17
Smaller Files
An analysis of the exposed directory has identified a text file containing a target list with approximately 170,000 URLs, with the attacker splitting it into 17 smaller files containing about 10,000 URLs each to more efficiently parse the set.
Metrics
victims
11
X神订制全站劫持按浏览器语言跳转)\Dll\Release\Demo.Pdb C:\Users\Administrator\Desktop\2025
The BadIIS samples used in this activity contain the following PDB paths:
C:\Users\Administrator\Desktop\2025-11-21 (x神订制全站劫持按浏览器语言跳转)\dll\Release\demo.pdb
C:\Users\Administrator\Desktop\2025-11-21 (x神订制全站劫持按浏览器语言跳转)\dll\x64\Release\demo.pdb
We…
Metrics
infrastructure
1.2.1
Software Version
C:\Users\iis\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\widestring-1.2.1\src\ucstring.rs
C:\Users\iis\Desktop\AI\EfsPotatoCpp\x64\Release\EfsPotato.pdb
C:\Users\Intel\Desktop\AI\EfsPotatoCPP\x64\Debug\EfsPotato.pdb
Other backdoors for p…
Metrics
financial
0
Generic-10060218
Generic-10060218-0
Win.
Intelligence Sources
Kaspersky
2026-08-26
Exploits and vulnerabilities in Q2 2026
Kaspersky
Talos Intelligence
2026-08-20
The Hacker News
2026-08-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-27T06:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
116x
organisation
Identified Entity
Kaspersky
entity
39x
vulnerability
Exploited CVE
CVE-2026-31431
cve
11x
timeline
Temporal Reference
Q1 2025
date
10x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
9x
target region
Target Country
Russian Federation
country
7x
tactic
Cyber Operation Type
Privilege Escalation
tactic
5x
industry
Targeted Sector
Technology
sector
4x
infrastructure
Affected Product
Windows
software
4x
general metric
Signal
36
signal
3x
general metric
Cve-2023
32,233
cve-2023
3x
general metric
Entities
24
entities
2x
malware
Offensive Tool
Sliver
tool
2x
general metric
Commands
29
commands
2x
general metric
Urls
170,000
urls
2x
general metric
Bit
32
bit
Contextual Telemetry
Context Block
19 METRICS
threat actor
APT Group
Equation
actor
general metric
Cve-2017
199
cve-2017
general metric
%
100
%
malware
Malware Payload
Havoc
tool
general metric
New Critical Vulnerabilities
9
new critical vulnerabilities
general metric
Top Vulnerabilities
10
top vulnerabilities
general metric
Top Vulnerability Types
6
top vulnerability types
data breach
Smaller Files
17
smaller files
general metric
Points
50
points
general metric
1 Process Injection
2
1 process injection
victims
X神订制全站劫持按浏览器语言跳转)\Dll\Release\Demo.Pdb C:\Users\Administrator\Desktop\2025
11
x神订制全站劫持按浏览器语言跳转)\dll\release\demo.pdb c:\users\administrator\desktop\2025
general metric
Windows Versions
13
windows versions
infrastructure
Software Version
1.2.1
version
campaign
Campaign
Campaign ID
operation
general metric
Generic-9883082
0
generic-9883082
general metric
Badiis-10060290
1
badiis-10060290
general metric
Comparands
21
comparands
general metric
Execution
404
execution
financial
Generic-10060218
0
generic-10060218
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.