A Chinese-speaking hacker group leverages AI to automate attacks on 170,000 vulnerable servers globally, targeting data theft and SEO fraud.
In early 2026, a cybercrime group known as UAT-10147, identified by Cisco Talos, began using artificial intelligence to automate attacks on internet-facing Windows and Linux web servers worldwide. This group has been linked to various criminal activities, including data theft and search engine optimisation (SEO) fraud.
Attack Overview
The UAT-10147 group targets a wide range of organisations, including government agencies, universities, media outlets, technology firms, and gaming companies across several countries, including Brazil, Bolivia, China, Canada, and Vietnam. By exploiting vulnerabilities in widely used software products, such as Zimbra and Telerik UI, the group launches automated attacks on approximately 170,000 identified servers.
Talos researchers, including Joey Chen, reported that the campaign was uncovered when investigators observed a compromised server communicating with a download server. An operational mistake left the server’s directory publicly accessible, revealing malware, scripts, tools, and lists of targeted URLs.
Tools and Techniques
UAT-10147 employs a sophisticated range of tools, including publicly available exploits and custom malware, to automate their attacks. They utilise a powerful backdoor known as SPECTRE, which is specifically designed for both Windows and Linux systems. The Windows variant features numerous commands, including commands for credential theft, keylogging, and even processes that can manipulate kernel callbacks to evade detection by endpoint security solutions.
On the Linux side, the group uses web shells and a custom-developed rootkit known as Specter, which hides itself and other processes while maintaining elevated privileges. Researchers believe that elements of the Linux rootkit may have been constructed with AI assistance due to the methodical and structured comments found in the source code.
Another notable aspect of this threat group is the integration of AI into their post-compromise operations. This includes the use of AI-generated documentation and scripts intended for exploit validation and troubleshooting, indicating a shift towards more sophisticated and semi-automated attack methodologies.
Threat Mitigation
Administrators of internet-facing servers are advised to promptly patch existing vulnerabilities and implement security measures, such as rotating ASP.NET MachineKeys and limiting administrative access. Monitoring for unexpected Microsoft Defender exclusions and suspicious scheduled tasks can aid in identifying compromised servers before attackers establish persistent access.
The presence of AI in cybercrime has significant implications for global cybersecurity. As cybercriminals develop increasingly automated and sophisticated methods of attack, traditional defensive strategies may need to evolve to counter these emerging threats.
As this situation develops, organisations are encouraged to stay vigilant and prioritise robust cybersecurity measures to protect sensitive data against the growing threat of AI-enhanced cybercrime activities.
Click Here For The Original Source.
