Security

Chinese Cybercrime Group Uses AI Tools to Automate Server Attacks

UAT-10147 deploys machine learning frameworks across a 170,000-target campaign hitting education, media, and gaming sectors worldwide.

Omega Editorial· August 24, 2026· 3 min read

Cybercriminals integrate AI across attack lifecycle

A Chinese-speaking cybercrime operation is weaponizing artificial intelligence tools to automate large-scale server compromises, targeting Windows and Linux systems in education, media, technology, and gaming organizations across five continents.

Cisco Talos researchers identified the threat actor, designated UAT-10147, after discovering an exposed directory containing a target list of approximately 170,000 URLs. The group splits these targets into manageable batches of 10,000 URLs each to systematically exploit known vulnerabilities for search engine optimization fraud and data theft.

The majority of compromised systems are located in Brazil, Bolivia, China, Canada, and Vietnam, though the target list shows intended victims span the United States, India, the United Kingdom, Germany, and the Netherlands.

AI tools automate exploitation and post-compromise operations

UAT-10147 distinguishes itself by integrating AI-powered frameworks at multiple stages of its operations. The group deploys PentestGPT, an open-source autonomous penetration testing tool, on command-and-control servers to scan web servers and execute proof-of-concept exploits automatically.

Researchers also found DeepAudit, an AI-driven vulnerability scanning framework, on the group's management infrastructure. While no evidence shows the attackers exploited vulnerabilities discovered by DeepAudit in victim environments, its presence suggests either planned use for identifying new attack vectors or defensive auditing of their own infrastructure.

The threat actor employs AI to refine exploits, troubleshoot logic errors, automate post-exploitation workflows, validate successful compromises, and generate operational documentation. Multiple Python scripts used in the campaign appear AI-generated, handling tasks from post-exploitation diagnostics to exfiltration traffic blending.

Cross-platform implant evades enterprise security

UAT-10147's toolkit centers on SPECTRE, a previously unreported cross-platform backdoor written in C. The Windows version supports 45 commands and uses bring-your-own-vulnerable-driver techniques to terminate endpoint detection and response processes from kernel space, rendering products from CrowdStrike, SentinelOne, and Microsoft Defender blind to malicious activity.

The Linux variant deploys a kernel-level rootkit that grants persistent control surviving reboots and most user-level security controls. Both versions employ weighted scoring mechanisms that trigger self-termination if sandbox indicators exceed threshold values.

Attack chains begin by exploiting known vulnerabilities in Zimbra, AjaxPro, Telerik UI, and Alibaba Nacos to achieve remote code execution. The group then deploys privilege escalation tools, establishes persistence through deceptive scheduled tasks, and installs backdoors including BadIIS malware, Gh0stCringe, Noodle RAT, and Quasar RAT.

Why it matters

This campaign demonstrates how commodity cybercrime operations are adopting AI tools to achieve enterprise-grade automation previously associated with nation-state actors. The 170,000-URL target list and systematic exploitation approach show threat actors scaling attacks beyond manual capacity. Organizations must assume adversaries can now identify and exploit vulnerabilities faster than traditional patch cycles, requiring accelerated vulnerability management and enhanced detection of automated reconnaissance patterns.

Cisco Talos first reported these findings in a two-part analysis published last week, providing detailed technical indicators and defensive recommendations for security teams.

#ai-powered-attacks#cybercrime#threat-intelligence#endpoint-security#vulnerability-exploitation#edr-evasion

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Top 5% of AI Users Create 12x the Security Risk, Akamai Finds

Power users engage in 18-prompt conversations and deploy shadow AI tools outside IT oversight, expanding enterprise attack surfaces.

Via AI Watch · Aug 24, 2026
Security· 4 min read

AI Chatbots Now Remember Your Conversations—Here's What They Know

OpenAI, Meta, Google, and Apple are expanding how their AI assistants use memory, activity data, and conversation history for personalization.

Via AI Watch · Aug 24, 2026
Security· 3 min read

Exploit Timelines Shrink from Years to Hours in AI Era

Security leaders must rethink application defense as weaponization windows collapse from 771 days to 4 hours by 2026.

Via AI Watch · Aug 24, 2026