SPECTRE Backdoor Bypasses Kernel-Level EDR Visibility Without Killing Security Processes
One daysingle sourceOne outlet reported this, once - no second voice in this corpus.
After publishing: 1 headline quietly rewritten1 change
- techtimes.comseen 2 Sept, 23:59headline rewritten
SPECTRE Backdoor Blinds CrowdStrike and SentinelOne at Kernel Level Without Killing ThemSPECTRE Backdoor Bypasses Kernel-Level EDR Visibility Without Killing Security Processes
All 1 reports on Wed, 26 August 2026
What it is about
Justin Sullivan GettyBaron SameditGelei DengCrowdstrike FalconAlibaba NacosMicrosoftBoliviaTaiwanChinaCanadaCalifornia, United StatesVietnamChineseBrazilNanyang, Henan, China
Who published it, and when
How it spread - 1 original report
Wed, 26 August 2026
1 report- techtimes.com16:18first to reportedited after publishing
previously
SPECTRE Backdoor Blinds CrowdStrike and SentinelOne at Kernel Level Without Killing ThemSPECTRE backdoor, deployed by post-compromise by Chinese-speaking hacker group UAT-10147 after gaining admin access, can strip kernel-level visibility from EDR products using BYOVD callback unlinking -- leaving security dashboards green while process monitoring goes dark. HVCI or WDAC driver