New 'SPECTRE' Malware Uses Advanced Tricks to Hide from Security Software
Cybersecurity researchers at Cisco Talos have uncovered a new malicious tool called SPECTRE, deployed by a threat group tracked as UAT-10147. This implant marks a step up in commodity hacking tools, combining several dangerous capabilities into one package: it can operate across both Windows and Linux systems, communicate with attacker-controlled servers, inject malicious code into legitimate processes, and steal saved credentials.
What makes SPECTRE particularly concerning is its ability to actively fight back against security defences. It includes anti-analysis features designed to frustrate researchers and automated detection tools, and it can exploit a technique known as 'Bring Your Own Vulnerable Driver' (BYOVD) to bypass endpoint detection and response (EDR) software at the kernel level — essentially disabling the deepest layer of a computer's security defences from the inside.
For small and medium businesses, this development is a reminder that modern malware is increasingly built to slip past traditional antivirus and EDR tools rather than simply avoid them. Businesses relying solely on standard endpoint protection may find such advanced threats harder to catch once they've gained a foothold, making layered defences and vigilant monitoring more important than ever.