UAT-10147: Chinese-Speaking Group Leverages AI to Scale Attacks on Windows and Linux Web Servers
A sophisticated Chinese-speaking cybercrime group called UAT-10147 has emerged as one of the most skilled groups of its kind, leveraging artificial intelligence tools to scale attacks on Windows and Linux web servers worldwide. According to research from Cisco Talos, this group is developing a cross-platform implant called SPECTRE that combines EDR bypass, credential theft, and a Linux rootkit into a single package.
The group's primary driver is financial exploitation through SEO fraud and data theft. UAT-10147 targets the education, media, technology, and gaming sectors, with the highest concentration of victims in Brazil, Bolivia, China, Canada, and Vietnam. However, the target list reveals that the top five target countries are the United States, India, the United Kingdom, Germany, and the Netherlands.
The group uses AI-assisted automation to achieve scale previously requiring larger teams. They employ tools like PentestGPT and DeepAudit to refine exploits, automate post-exploitation workflows, and validate exploits. This approach allows them to process tens of thousands of targets simultaneously.