UAT-10147 Uses Agentic AI to Target 170,000 Web Servers Worldwide
Updated
Updated · blog.talosintelligence.com · Aug 20
UAT-10147 Uses Agentic AI to Target 170,000 Web Servers Worldwide
3 articles · Updated · blog.talosintelligence.com · Aug 20
Summary
Cisco Talos said UAT-10147 folded agentic AI into real intrusions, using it for exploit refinement, reconnaissance, payload generation, validation and persistence on Windows and Linux web servers.
About 170,000 target URLs were found on the group’s exposed C2 infrastructure, showing a scaled campaign against organizations in government, education, media, technology and gaming across countries including Brazil, Canada, China and Vietnam.
Talos said the financially motivated group relies on known one-day flaws such as Zimbra, Nacos, Telerik and Dirty Pipe, then automates post-compromise work with tools including Metasploit, PentestGPT, DeepAudit and ysoserial.
Recovered AI-generated playbooks and scripts documented low-noise ViewState exploitation, webhook-based validation, SPECTRE and web-shell deployment, and privilege escalation via Potato-style exploits or Linux kernel flaws.
Talos assessed with moderate-to-high confidence that UAT-10147 represents an emerging class of cybercriminals using semi-autonomous AI workflows to scale advanced attacks while lowering the expertise needed after compromise.
How did a simple server mistake expose a massive AI-driven cyberattack targeting 170,000 global networks?
Why are elite cybercriminals deploying advanced AI and custom rootkits just to manipulate search engine rankings?
UAT-10147’s 170,000-Target AI-Powered Attack: How Chinese Cybercriminals Are Automating Global Web Server Compromise
Overview
In early 2026, Cisco Talos researchers discovered the Chinese-speaking cybercrime group UAT-10147 after the group left an open directory exposed on their server. UAT-10147 used agentic AI systems to automate and scale attacks, splitting a massive target list for efficient scanning and deploying the BadIIS module to hijack website content and manipulate search engine results. Their AI-generated exfiltration scripts blended stolen data with normal SaaS traffic, helping them avoid detection. The group also used advanced malware like SPECTRE and the Specter rootkit, which performed anti-sandbox checks and blinded security products, creating persistent and stealthy control over compromised hosts while operating largely undetected.