Cybercrime Group UAT-10147 Targets Servers Worldwide
The cybercrime group UAT-10147 has launched targeted attacks on servers in various sectors worldwide, particularly in Brazil and China.
Cybersecurity researchers have released details about a Chinese-speaking cybercrime group known as UAT-10147. This group specializes in attacks on Windows and Linux web servers, targeting various sectors such as education, media, technology, and gaming. The attacks are global in nature, with the majority of targets found in countries like Brazil, Bolivia, China, Canada, and Vietnam.
The threat posed by UAT-10147 became known through the discovery of an open source code that allows the group to scale their attacks. Researchers have found that the group employs advanced techniques to carry out their attacks, including the use of SPECTRE, a well-known security vulnerability that enables attackers to steal sensitive data. This technique is used in combination with an EDR bypass (Endpoint Detection and Response) to circumvent security measures.
Another notable aspect of UAT-10147's attacks is the use of a Linux rootkit. This rootkit allows attackers to gain unnoticed access to the affected systems and conceal their activities. The use of rootkits is a common tactic among cybercriminals, as they enable control over a system without the user noticing.
Geographical Distribution of Attacks
The attacks by UAT-10147 are primarily focused on specific geographical regions. Brazil and Bolivia are the most affected countries, followed by China, Canada, and Vietnam. These countries have a high density of web servers operating in the affected sectors, making them attractive targets for the cybercrime group.
The choice of these specific countries may indicate strategic planning by the group to achieve maximum impact. The affected sectors, particularly education and technology, are critical to the national infrastructure of these countries. A successful attack could not only cause financial damage but also undermine trust in the digital infrastructure.
Reactions from the Security Community
The discovery of UAT-10147's activities has raised concerns within the cybersecurity community. Experts warn of the potential consequences of such attacks and emphasize the need to strengthen security measures. Companies in the affected sectors are urged to review their systems and ensure they are equipped to defend against such threats.
Security authorities in the affected countries have also responded and are working to analyze the threat posed by UAT-10147 and take appropriate measures. Cooperation between international security agencies is seen as crucial to combat the activities of such cybercrime groups and ensure the security of the digital infrastructure.
The revelations about UAT-10147 highlight the ongoing threat of cybercrime and the necessity of taking proactive measures. The group employs advanced techniques and strategies to carry out their attacks, increasing the challenges for the security community. Ongoing investigations and analyses will be critical to understanding and combating the activities of this group.
comment Kommentare (0)
Noch keine Kommentare. Schreiben Sie den ersten!
Kommentar hinterlassen