SPECTRE cross-platform backdoor with Linux rootkit
Malware Activity
Summary
Hide ▲
Show ▼
The SPECTRE malware activity adds a cross-platform backdoor and kernel-level EDR bypass, giving operators persistent control over infected Windows and Linux hosts. Talos says the implant also supports HTTPS C2, credential theft, and anti-analysis protections, while the Linux variant loads a Specter rootkit. The first observed use dates to April 2026, showing a recently emerged toolset built for stealth and durable access.
Related Happenings
UAT-7810 malware toolkit expansion with LONGLEASH, DOGLEASH, and JARLEASH
Malware Activity
H score27
First: 08.07.2026 17:30
Last: 08.07.2026 17:30
Sources 1
About this happening:
Chinese threat actor UAT-7810 is actively refining its bespoke malware to expand the LapDogs ORB network by breaking into internet-facing networking devices. The a...
UAT-7810 malware toolkit expansion with LONGLEASH, DOGLEASH, and JARLEASH
Malware ActivityAbout this happening: Chinese threat actor UAT-7810 is actively refining its bespoke malware to expand the LapDogs ORB network by breaking into internet-facing networking devices. The a...
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityAbout this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance
Technical Analysis
H score34
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS...
ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance
Technical AnalysisAbout this happening: ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS...
Fast16 malware framework technical analysis of svcmgmt.exe and fast16.sys
Technical Analysis
H score22
First: 27.04.2026 12:10
Last: 27.04.2026 12:10
Sources 1
About this happening:
Researchers uncovered Fast16, a 2005-era malware framework that shows how a Lua-based implant could sabotage software years before Stuxnet. The analysis matters be...
Fast16 malware framework technical analysis of svcmgmt.exe and fast16.sys
Technical AnalysisAbout this happening: Researchers uncovered Fast16, a 2005-era malware framework that shows how a Lua-based implant could sabotage software years before Stuxnet. The analysis matters be...
GNU InetUtils telnetd remote authentication bypass (CVE-2026-24061)
Vulnerability
H score66
First: 22.01.2026 18:30
Last: 22.01.2026 18:30
Sources 1
About this happening:
A critical remote authentication bypass in GNU InetUtils telnetd lets attackers skip login and reach root access on affected releases. The flaw is tracked as CVE-202...
GNU InetUtils telnetd remote authentication bypass (CVE-2026-24061)
VulnerabilityAbout this happening: A critical remote authentication bypass in GNU InetUtils telnetd lets attackers skip login and reach root access on affected releases. The flaw is tracked as CVE-202...
Timeline
-
24.08.2026 11:08 2 articles · 12h ago
SPECTRE uses cross-platform C2 and a Linux kernel rootkit
Technical Analysis UpdateThe SPECTRE implant gives operators persistent control over Windows and Linux hosts through HTTPS command-and-control, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass. Its Linux variant runs anti-sandbox checks before establishing C2 and loads a kernel module rootkit named Specter, and Talos says the first observed use of the implant dates back to April 2026.
Show sources
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit — thehackernews.com — 24.08.2026 11:08
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit — thehackernews.com — 24.08.2026 11:08