Chinese group UAT-10147 hijacks web servers with AI tools
Cisco Talos found a Chinese-speaking cybercrime group called UAT-10147 breaking into vulnerable Windows and Linux web servers to steal data and hijack search results for profit. An operational mistake exposed the group's own server, revealing a target list of about 170,000 URLs across government, education, media, technology, and gaming organizations. Confirmed victims were seen in Brazil, Bolivia, China, Canada, and Vietnam, and Talos says the group is using AI tools, including an agent called PentestGPT, to help write exploit code and run post-compromise attack playbooks, including a backdoor called SPECTRE with a Linux rootkit component named Specter.
- Started
- Aug 14, 2026
- Latest activity
- Aug 26, 2026
- Attributed to
- UAT-10147Suspected
- Where
- Brazil, Bolivia, China, Canada, Vietnam
- Sectors
- Government, Education, Media, Technology, Multiple sectors
- Scale
- a target list of roughly 170,000 URLs found on the group's own exposed server, not a confirmed victim count
Current status
A September 2 Infosec.ge summary added no new victims, restoration, containment, or closure, and no confirmed activity has been reported since August 26.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Cisco Talos tracks the group as UAT-10147 based on language and tooling analysis; no government has confirmed the group's identity or location.
Impact
Compromised servers were used to steal data, install backdoors and a kernel-level rootkit, and redirect search traffic to ads and gambling sites for profit. The SPECTRE backdoor can also silently disable the visibility of security tools such as CrowdStrike, SentinelOne, and Microsoft Defender on infected Windows servers without shutting them down or triggering an alert.
What to do
IT teams should patch the exploited flaws in Zimbra, AjaxPro, Nacos, and Telerik UI and Linux kernel bugs like Dirty Pipe and Baron Samedit, check IIS servers for unfamiliar directories or scheduled tasks, and turn on Windows features like Hypervisor-Protected Code Integrity or Windows Defender Application Control driver allowlisting so old vulnerable drivers cannot be loaded to attack security software.
Timeline
-
Sep 2, 2026
Infosec.ge published a technical summary of SPECTRE's kernel-level security-tool evasion. It reported no new victims, restoration, containment, or closure.
Dormantinfosec.ge -
Aug 28, 2026
Hexnode published a threat-watch summary of UAT-10147 and SPECTRE. It repeated the known malware and AI-assisted attack details and reported no new victims, containment, or closure.
Dormanthexnode.com -
Aug 27, 2026
Information Security republished earlier Cisco Talos and The Hacker News findings, with no new victims, containment, or closure reported.
Activeinformationsecurity.com.tw -
Aug 26, 2026
Tech Times published a technical deep dive on SPECTRE's kernel-level evasion, explaining that the backdoor loads an old, legitimately signed but vulnerable Windows driver to gain kernel access, then removes the internal hooks that CrowdStrike, SentinelOne, and Microsoft Defender rely on for visibility, so the security software keeps showing a healthy status while blind to attacker activity. The report cited a Cisco Talos follow-up published August 20, 2026 and named no new victims.
Activetechtimes.com -
Aug 25, 2026
CSO Online repeated Cisco Talos's findings and added expert warnings that AI can shorten the time defenders have to respond. It did not name new victims or report containment or closure.
Activecsoonline.com -
Aug 24, 2026
DailySecu (South Korea) republished the Cisco Talos findings on UAT-10147 for a Korean-language audience, repeating the same 170,000-URL target list and AI tooling details with no new victims or closure reported.
Activedailysecu.com -
Aug 24, 2026
iThome (Taiwan) republished the Talos findings on UAT-10147 for a Chinese-language audience, with no new victims or resolution reported.
Activeithome.com.tw -
Aug 22, 2026
SecurityLab.ru covered the same Talos research, emphasizing that UAT-10147 now uses AI to search for vulnerabilities and prepare attack tools rather than just assist with code.
Activesecuritylab.ru -
Aug 20, 2026
CyberInsider reported the group's SPECTRE backdoor and Specter Linux rootkit, noting the campaign was discovered by Talos in early 2026.
Activecyberinsider.com -
Aug 18, 2026
GBHackers detailed the BadIIS malware and confirmed victims in Brazil, Bolivia, China, Canada, and Vietnam.
Activegbhackers.com -
Aug 14, 2026
Cyber Security News reported Cisco Talos findings on UAT-10147 using AI-generated exploit scripts against a 170,000-URL target list.
Activecybersecuritynews.com
Sources
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Cisco Talos Aug 18, 2026
- Chinese hackers use AI to automate attacks on 170,000 servers CyberInsider Aug 20, 2026
- Chinese attackers steal data and hijack websites GBHackers Aug 18, 2026
- Chinese attackers automate attacks on web servers Cyber Security News Aug 14, 2026
- 中國駭客UAT-10147鎖定易受攻擊伺服器,透過AI打造的工具從事攻擊 iThome Aug 24, 2026
- AI assistant instead of a team of coders: neural network writes exploits and assembles backdoors for UAT-10147 SecurityLab.ru Aug 22, 2026 unverified
- UAT-10147: PentestGPT und SPECTRE - Talos zeigt die Kette BLOGSPAN.NET Aug 20, 2026
- 중국 해킹그룹 UAT-10147, AI로 17만 웹서버 공격 자동화 DailySecu Aug 24, 2026
- AI helps Chinese-speaking hackers speed up attacks on exposed servers CSO Online Aug 25, 2026
- SPECTRE Backdoor Blinds CrowdStrike and SentinelOne at Kernel Level Without Killing Them Tech Times Aug 26, 2026
- UAT-10147 deploys SPECTRE: a cross-platform implant with Linux rootkit and BYOVD capabilities Cisco Talos Aug 20, 2026
- UAT-10147 uses AI to scale server attacks The Hacker News
- 中國語系駭客UAT-10147 導入AI並部署新跨平台後門 SPECTRE Information Security Aug 27, 2026
- UAT-10147 and SPECTRE: When EDRs go blind at the kernel level Infosec.ge Sep 2, 2026
- UAT-10147 SPECTRE Backdoor: AI-Driven EDR Bypass Attack Hexnode Aug 28, 2026
Related reports
- Chinese attackers automate attacks on web servers Aug 21, 2026
- Chinese attackers steal data and hijack websites Aug 18, 2026