Chinese Hackers Leverage AI to Automate Web Server Exploits
Chinese hackers have been using AI-assisted tools to exploit vulnerable web servers and automate attacks. The group, known as UAT-10147, targeted internet-facing Windows and Linux systems in various countries, including government, education, media, technology, and gaming sectors.
The attackers used publicly known remote-code-execution weaknesses to gain initial access, followed by AI-generated instructions, scripts, and testing steps. Cisco Talos identified the activity and found that the operators mixed public exploits with AI-generated content to carry out complex intrusions at a greater scale.
The use of AI in this campaign is not about making attacks fully independent of people but rather repeating established techniques more efficiently. The group combined workflows with established offensive frameworks, allowing them to find weaknesses, build payloads, test results, and document the next action.