Linux infection chain | Image: Cisco Talos
At a glance
| Factor | Details |
|---|---|
| Actor | UAT-10147 (Suspected Chinese-speaking cybercrime threat group) |
| Activity Type | Search engine optimization (SEO) fraud, data theft, and automated server exploitation |
| Targets | Windows and Linux web servers in government, education, technology, media, and gaming |
| Scale | Over 170,000 target URLs identified across more than 15 countries |
| Status | Active cybercrime threat under ongoing industry monitoring |
| Source | Cisco Talos Intelligence Group |
Researchers at Cisco Talos recently uncovered a cybercrime campaign powered by UAT-10147 agentic AI tools. The Chinese-speaking threat group targets vulnerable Windows and Linux web servers around the world. In addition, the operators combine automated artificial intelligence workflows with standard offensive exploit frameworks to steal data.
What Happened
In early 2026, security analysts identified an active intrusion cluster tracked as UAT-10147. The attackers actively scanned global networks for known security vulnerabilities to gain initial access.
According to a detailed threat report by Cisco Talos, the group deployed malicious scripts to compromise high-value targets. Talos researchers noted that “the actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations.”
Furthermore, an operational security failure by the threat actor exposed their staging infrastructure. Analysts discovered an open directory on a download server at the IP address 139.180.197[.]150. Consequently, investigators inspected internal playbooks, execution scripts, and attack logs directly from the adversary.
Who Is Behind It
Cisco Talos assesses with moderate-to-high confidence that UAT-10147 is a financially motivated cybercrime group. Linguistic evidence and script artifacts strongly suggest Chinese-speaking operators. For example, researchers discovered the username “dajiba” in server directories, which is a known Chinese pinyin slang term.
Additionally, the threat actor organized target lists using the letter “w” to denote ten thousand items. This naming convention directly reflects standard Chinese numerical counting units.
Importantly, the group focuses on financial gain through SEO fraud and intellectual property theft. Talos highlighted that “UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persistence workflows.” This automated capability allows less experienced operators to conduct complex network attacks at scale.
Impact and Scale
The campaign compromises critical internet-exposed web servers across multiple continents. Specifically, confirmed victim servers operate in Brazil, Bolivia, Canada, China, and Vietnam.
Moreover, telemetry recovered from the adversary’s open directory revealed a massive target list of roughly 170,000 URLs. The threat actor divided this master file into 17 smaller batches of 10,000 addresses to speed up scanning.
According to geographic data, the United States accounted for the largest target share with over 52,000 URLs. Meanwhile, India, the United Kingdom, Germany, and the Netherlands followed with thousands of targeted systems each. The campaign impacted organizations across government agencies, universities, media outlets, technology firms, and online gaming platforms.
AI-Driven Post-Compromise Workflows
The adversary adopts novel post-exploitation techniques by embedding artificial intelligence into attack pipelines. Specifically, the operators use PentestGPT to automate vulnerability scanning and execute proof-of-concept exploits on target systems.
Furthermore, UAT-10147 uses the DeepAudit framework to analyze source code for software flaws. The group also generates automated documentation and remediation logic to verify intrusion success.
As Talos reported, “Talos observed AI-generated operational playbooks, exploit automation scripts, and troubleshooting logic supporting real-world intrusions.”
For instance, the group created custom Python automation scripts to execute ASP.NET ViewState deserialization attacks. The AI-generated playbooks instructed the attacker to monitor specific HTTP 500 error messages to validate stolen MachineKey credentials. When standard time-based blind testing failed, the AI workflow adapted by deploying out-of-band callbacks to webhook endpoints.
Infection Chains on Windows and Linux
The threat actor tailors its attack chain depending on the victim operating system. On Windows servers, the group exploits one-day web flaws to obtain remote code execution.
Subsequently, attackers execute batch scripts such as “back.bat” and “bai.bat” using certutil. These scripts deploy the EfsPotato privilege escalation tool and add malicious paths to Windows Defender exclusion lists. Next, the threat actor installs the BadIIS module and drops backdoors like QuasarRAT and SPECTRE. Finally, the attacker creates rogue administrator accounts and scheduled tasks to retain access.
Linux Attack Vectors
In contrast, Linux servers face initial exploitation through web shells. Once inside, the threat actor attempts local privilege escalation using known kernel exploits. These flaws include Dirty Pipe (CVE-2022-0847), Baron Samedit (CVE-2021-3156), and CVE-2022-0995. After obtaining root privileges, the operators deploy implants such as NoodleRAT and Meterpreter.
Defensive Steps and Mitigation
Organizations must strengthen perimeter defenses against UAT-10147 agentic AI attacks. Because the group relies on publicly known vulnerabilities, patching exposed web applications remains essential.
First, administrators should audit internet-facing systems for legacy flaws in Zimbra, Telerik UI, and Nacos frameworks. Second, security teams must protect ASP.NET MachineKey configurations to stop ViewState deserialization attacks.
Furthermore, defenders should monitor PowerShell activity, unexpected certutil downloads, and unusual IIS module installations. Restricting SeImpersonatePrivilege on IIS application pools also blocks Potato-style privilege escalation. By enforcing strict access controls and updating software promptly, enterprises can block these automated intrusion attempts.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.