UAT-10147 Integrates AI Into Server Intrusions
Cisco Talos disclosed on August 20 that UAT-10147, a Chinese-speaking cybercrime group, has targeted vulnerable Windows and Linux web servers globally using AI-assisted exploitation and post-compromise workflows. Talos reports that the group deploys the cross-platform SPECTRE implant, Linux rootkit capabilities, and Bring Your Own Vulnerable Driver techniques to neutralize endpoint defenses. The Hacker News reported an exposed target list containing approximately 170,000 URLs.
Cisco Talos disclosed on August 20 that UAT-10147, a Chinese-speaking cybercrime group, has targeted internet-exposed Windows and Linux web servers across government, education, media, technology, and gaming. Talos reported victims in Brazil, Bolivia, China, Canada, and Vietnam, and identified publicly disclosed vulnerabilities as the group's initial-access mechanism.
Talos assesses with moderate-to-high confidence that UAT-10147 is a financially motivated operator using agentic AI systems across exploitation, reconnaissance, payload generation, validation, persistence, and operational documentation. The reported activity goes beyond one-off code generation: Talos observed iterative exploit refinement, adaptive troubleshooting, automated post-exploitation tasks, and validation workflows during real intrusions.
Large-scale targeting and automated intrusion
The Hacker News reported that investigators found an exposed directory communicating with a compromised machine. A text file in that directory contained approximately 170,000 URLs, split into 17 files of about 10,000 URLs each. The top destinations in the target list were the United States, India, the United Kingdom, Germany, and the Netherlands, according to the publication.
Talos reported that the group used publicly available offensive frameworks and utilities, including Metasploit, ysoserial, PentestGPT, DeepAudit, and privilege-escalation exploits. The Hacker News described attack chains in which known vulnerabilities were exploited for remote code execution on websites or IIS servers, followed by automated malware deployment for SEO fraud or data theft.
The reported tooling indicates that internet-facing server exposure remains the central defensive boundary in this campaign. Organizations running IIS or Linux-hosted web applications can reduce the available attack surface through timely patching, removal of unnecessary public services, and monitoring for anomalous web-server child processes and outbound connections. Those are standard controls for comparable web-server intrusion campaigns, rather than conclusions about any individual victim's environment.
SPECTRE and defense evasion
In a separate report, Talos described SPECTRE as a cross-platform implant used by UAT-10147. According to Talos, the implant includes command-and-control functionality, process injection, credential theft, anti-analysis protections, and mechanisms for evading endpoint detection and response tools.
Talos also documented the group's use of Bring Your Own Vulnerable Driver, or BYOVD, techniques. BYOVD attacks abuse legitimate but vulnerable kernel drivers to obtain privileged capabilities that can be used to interfere with security tooling. Talos further identified a custom Linux rootkit called Specter and reported in-memory web-shell deployment techniques alongside both custom and open-source tools.
The vendor's recovered-source-code analysis suggested that portions of SPECTRE and the Specter rootkit may have incorporated AI-assisted development workflows. That finding is distinct from confirmation that a particular model generated specific code. Talos characterized the evidence as indications of AI-assisted development rather than definitive attribution of code authorship to an AI system.
What the campaign changes for defenders
Talos frames UAT-10147 as an example of AI being integrated into an intrusion workflow rather than used only for isolated scripting assistance. For security engineering teams, that distinction matters because automation can accelerate target enumeration, exploit testing, troubleshooting, and repeatable persistence after a vulnerability is discovered.
Across comparable campaigns, defenders benefit from correlating patch-management data with web-server telemetry, EDR tamper alerts, suspicious driver loads, privilege-escalation activity, and web-shell indicators. The combination of cross-platform malware and AI-supported operational automation also reinforces the need for detection coverage across both Windows and Linux server fleets, rather than treating the two environments as separate threat models.
Key Points
- 1Talos links UAT-10147 to AI-assisted exploit refinement and post-compromise automation, increasing the operational speed of scalable server attacks.
- 2SPECTRE combines cross-platform command and control, credential theft, process injection, and defense evasion, expanding detection requirements across Windows and Linux.
- 3Comparable AI-enabled intrusion operations make rapid patching, web-server telemetry, and EDR tamper monitoring more important for exposed infrastructure.
Scoring Rationale
The report documents a notable use of AI-assisted workflows in real-world, large-scale server compromise operations, with relevance for security engineers and ML practitioners building defensive systems. Its cross-platform malware, EDR-bypass techniques, and large target list elevate the operational significance beyond a routine malware disclosure.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
