talos · Crawled Sep 1, 2026

Is Cyber missing the Marque?

15 IoCs
Read original article ↗

AI Summary

UAT-10147, a Chinese-speaking cybercrime group, is leveraging agentic AI to automate and scale sophisticated post-compromise operations across global web servers. The group uses AI to generate operational playbooks, customize malware, and dynamically validate exploit paths, including through stolen ASP.NET MachineKeys for ViewState deserialization attacks. A newly identified backdoor called SPECTRE features a cross-platform capability with a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) techniques designed to evade endpoint detection and response (EDR) solutions. Defenders are advised to patch internet-facing applications, secure MachineKeys, block vulnerable drivers, and monitor for anomalous HTTP 500 errors used during exploitation.

AI-extracted · verify before operational use

Indicators of Compromise 15 extracted

Type Value Detail
SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 Details →
MD5 2915b3f8b703eb744fc54c81f4a9c67f Details →
Filename VID001.exe Details →
SHA-256 a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 Details →
MD5 7bdbd180c081fa63ca94f9c22c457376 Details →
Filename d4aa3e7010220ad1b458fac17039c274_62_Exe.exe Details →
SHA-256 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 Details →
MD5 8ef476fa2322d063896830f85bac2e7f Details →
Filename WebCompanion.exe Details →
SHA-256 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 Details →
MD5 c2efb2dcacba6d3ccc175b6ce1b7ed0a Details →
Filename tmp00055df5.dll Details →
SHA-256 c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 Details →
MD5 9a47c4d379998ade2f8f99e23a630c06 Details →
Filename WCInstaller_NonAdmin.exe Details →