
Cisco Talos has identified a financially motivated Chinese-speaking cybercrime group that is using artificial intelligence alongside conventional offensive tools to automate parts of attacks against vulnerable Windows and Linux web servers.
The group, tracked by Talos as UAT-10147, was discovered in early 2026 targeting internet-exposed servers in multiple regions. Investigators found affected systems in Brazil, Bolivia, China, Canada and Vietnam, belonging to organizations in government, education, media, technology and gaming. Talos said the activity included search engine optimization fraud and data theft, with attackers using compromised web servers to maintain access and deploy additional malware.
In a report published on August 20, Cisco Talos said UAT-10147 had incorporated AI-assisted tooling into exploitation, reconnaissance, payload generation, validation and persistence. The researchers observed AI-generated operational playbooks, exploit automation scripts and troubleshooting procedures being used in real intrusions.
Talos said the evidence points to a move beyond using generative AI for simple programming assistance. The group demonstrated iterative exploit refinement, adaptive troubleshooting, automated post-exploitation activity, exploit validation and the generation of operational documentation. Cisco assessed with moderate-to-high confidence that UAT-10147 belongs to an emerging group of financially motivated operators using agentic AI systems to organize offensive activity at scale.
The investigation also uncovered an approximately 170,000-URL target list on one of the actor’s command-and-control servers. The URLs were divided into 17 files containing about 10,000 addresses each, apparently to make large-scale scanning more manageable. Talos said the list represents potential targets and does not establish that all of the listed servers were compromised.
UAT-10147 used both publicly disclosed vulnerabilities and AI-assisted offensive tools to obtain access. Cisco said the group exploited vulnerabilities including CVE-2022-27925 in Zimbra Collaboration Suite, CVE-2021-23758 in AjaxPro, CVE-2021-29441 and CVE-2021-29442 in the Nacos framework, and CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX.
On Linux systems, Talos observed the use of several known privilege-escalation vulnerabilities, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904 and CVE-2022-0847, commonly known as Dirty Pipe. The activity shows that the operation relied heavily on already disclosed weaknesses rather than depending solely on previously unknown vulnerabilities.
The attackers also used established offensive frameworks. Talos identified Metasploit, ysoserial, PentestGPT and DeepAudit among the tools present in the operation, alongside several privilege-escalation utilities and custom malware.
DeepAudit was found installed on the group’s management server and was assessed by Talos as a tool the attackers intended to use for source-code vulnerability scanning, including against websites and third-party libraries. However, Cisco explicitly said it had not directly observed the group exploiting a vulnerability discovered by DeepAudit against a victim environment. Talos also said DeepAudit could have been used to audit the attackers’ own infrastructure or tools.
PentestGPT was observed in more direct use. Talos found the framework installed on a command-and-control server and observed it being used to dynamically scan web servers and execute relevant proof-of-concept exploits. Cisco said the actor successfully exploited a website using the framework and collected information from the compromised machine.
One of the clearest examples of AI being integrated into the attack process involved an ASP.NET ViewState deserialization attack. Talos recovered an AI-generated operational guide covering exploitation, payload generation, validation, reconnaissance, persistence and privilege escalation.
The accompanying scripts automated several stages of the process, including checking write permissions, deploying an implant, installing a web shell and collecting information from compromised servers. The workflow also incorporated methods for determining whether exploitation had succeeded and documented lessons from failed attempts. Talos said the attackers used out-of-band callbacks to confirm execution after discovering that time-based tests were unreliable for this particular exploitation method.
After successful execution, the recovered workflow directed systematic collection of information about the compromised system, including privileges, web directories, IIS configuration, network interfaces and running processes. The collected data was sent to remote infrastructure through HTTP requests.
The same AI-generated material described several methods of maintaining access. The preferred option was deployment of the group’s SPECTRE implant, with web shells and a PowerShell-based reverse shell documented as alternatives. The playbook also described privilege escalation from the IIS worker process to the Windows SYSTEM account.
Talos said it recovered a separate findings log from an actual intrusion that recorded successful ViewState exploitation against a real IIS server. The log contained details about the targeted system and more than 12 HTTP callbacks, which confirmed successful execution and returned reconnaissance information from the server.
The operation continued after initial access with conventional malware and persistence techniques. On Windows, Talos observed scripts downloading an EfsPotato privilege-escalation tool and the QuasarRAT payload. The attackers modified Windows Defender exclusions for IIS directories and created scheduled tasks named “Google Chrome Start” that executed malware with elevated privileges when users logged in.
The attackers also created a local account and added it to the Administrators and Remote Desktop Users groups, providing another route to persistent privileged access. Cisco observed other implants deployed during the campaign, including Gh0stCringe and SPECTRE.
The SPECTRE investigation published by Talos provides further detail on the group’s custom malware. Cisco describes SPECTRE as a cross-platform implant with command-and-control capabilities, process injection, credential theft, anti-analysis features and mechanisms designed to interfere with endpoint security monitoring.
The Windows version includes capabilities for command execution, file operations, process management, credential theft and other post-compromise activities. Talos also observed the use of vulnerable drivers associated with CVE-2019-16098 and CVE-2021-21551 to obtain kernel-level access and interfere with security software mechanisms.
On Linux, the SPECTRE ecosystem includes a kernel rootkit known as Specter. Talos found the rootkit using a name resembling a legitimate Linux module and a systemd service designed to load it early in the boot process. The researchers said it can hide processes and its own kernel module and can provide the implant with root-level access.
Talos assessed with medium confidence that AI assistance and human expertise were involved in development of the Linux rootkit. Cisco did not conclude that artificial intelligence independently created the malware.
The campaign also involved BadIIS, an IIS malware used in the group’s SEO fraud activity, and a separate C# engine designed to manipulate search-related behavior on compromised sites. Talos observed configuration targeting Vietnamese users and the Cốc Cốc browsing and search ecosystem.
Cisco said the overall operation combines known vulnerabilities, open-source offensive frameworks, AI-assisted exploitation and automation, custom malware and persistence techniques. The investigation does not show that an AI system independently carried out an entire cyberattack or compromised all of the approximately 170,000 URLs identified in the target list.
Instead, the evidence shows attackers incorporating AI into multiple stages of an existing intrusion operation. According to Talos, that combination can reduce the amount of human effort required to develop, test and repeatedly apply exploitation workflows against vulnerable web servers.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


