Back to Feed
MalwareAug 24, 2026

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Chinese cybercrime group UAT-10147 uses AI to scale server attacks, deploying SPECTRE with EDR bypass.

Summary

A Chinese-speaking cybercrime group, UAT-10147, is targeting Windows and Linux web servers globally, leveraging AI to enhance various attack phases including exploitation, reconnaissance, and payload generation. The group utilizes publicly disclosed vulnerabilities and open-source frameworks to gain initial access and deploy malware for SEO fraud and data theft, with a significant focus on targets in Brazil, Bolivia, China, Canada, and Vietnam.

Full text

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit Ravie LakshmananAug 24, 2026Cybercrime / Malware Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at "139.180.197[.]150," which was observed communicating with one of the compromised machines. "The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale," Cisco Talos said in a two-part report published last week. The actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence." UAT-10147 has been described as a threat actor that conducts search engine optimization (SEO) fraud and data theft, while integrating artificial intelligence (AI)-powered tools at various phases of the attack cycle to facilitate exploitation, reconnaissance, payload generation, validation, and persistence. Specifically, this involves using AI to refine exploits, troubleshoot logic, automate post-exploitation workflows, validate exploits, and generate operational documentation, indicating an attempt to implement offensive tradecraft at scale. An analysis of the exposed directory has identified a text file containing a target list with approximately 170,000 URLs, with the attacker splitting it into 17 smaller files containing about 10,000 URLs each to more efficiently parse the set. The top five destinations based on the target list consist of the U.S., India, the U.K., Germany, and the Netherlands. Attack chains involve exploiting known flaws to achieve remote code execution (RCE) on a website or a vulnerable IIS server, and then run an automated script to install and deploy malware for SEO fraud or data stealing. Select instances entail the deployment of a web shell, which then paves the way for BadIIS and additional backdoors for persistent access. Some of the other steps undertaken by UAT-10147 is as follows - Using a batch script that employs certutil to download a privilege escalation tool ("EfsPotato"), a secondary batch script, and Quasar RAT from a remote server ("adminapi.tippusoni[.]in") Using EfsPotato to gain elevated system privileges, configure Microsoft Defender exclusions Deleting initial payloads to cover its tracks and thwart forensic analysis Deploying follow-on implants like Gh0stCringe and a previously unreported cross-platform implant dubbed SPECTRE Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start" Abusing the elevated privileges to download a third batch script, which then installs BadIIS Interestingly, the core BadIIS malware is the same specific variant that's known to operate under a malware-as-a-service (MaaS) model and is used by multiple Chinese-speaking cybercrime groups. The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847. Once root-level access is unlocked, the threat actor has been observed deploying multiple backdoors like Noodle RAT (a variant of Gh0st RAT and Rekoobe), SPECTRE, and Meterpreter to enable outbound connections to remote command-and-control (C2) infrastructure. Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos). "By routing exfiltrated data to a legitimate cloud-based configuration management service, the attackers effectively blend their traffic with normal administrative operations," Talos researcher Joey Chen said. "This infrastructure choice acts as an asynchronous exfiltration sink, allowing the adversaries to poll their own Nacos instance to verify successful exploitation across victims without the operational overhead or detection risk of establishing a persistent reverse shell or maintaining direct inbound connections." A notable aspect of UAT-10147's tradecraft concerns an AI-driven framework called DeepAudit for vulnerability scanning. Talos said it found no evidence of the threat actor exploiting vulnerabilities discovered by the tool in victim environments, although it was left accessible on the management server. This has raised the possibility that the attackers are planning on using DeepAudit to identify vulnerabilities within target environments. Conversely, it's also likely that it could be used to improve their own defensive posture by proactively auditing their own infrastructure and tooling to prevent potential exposure and compromise by other threat actors. UAT-10147 has also been found to install PentestGPT, an open-source autonomous pentesting framework, on their C2 server to scan web servers and execute relevant proof-of-concept exploits. In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands. Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects - Making use of the badsecrets library comprising publicly known or leaked ASP.NET MachineKey configurations, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()" Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant. The third script deploys the ASHX web shell onto the compromised IIS server via the same deserialization mechanism. The final script is responsible for blending exfiltration traffic with legitimate software-as-a-service (SaaS) traffic over HTTPS and transmitting webfoot enumeration, IIS site inventory, and privilege assessment details to a webhook endpoint. SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar. It communicates with a C2 server using HTTPS and supports as many as 45 commands that grant the operator extensive control over the infected endpoint. The first use of the implant by the threat actor dates back to April 2026. "The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality," Talos said. The Windows v

Indicators of Compromise

  • ip — 139.180.197.150
  • domain — adminapi.tippusoni.in
  • cve — CVE-2022-0995
  • cve — CVE-2021-3156
  • cve — CVE-2015-5287
  • cve — CVE-2015-3246
  • cve — CVE-2010-3904
  • cve — CVE-2022-0847
  • cve — CVE-2022-27925
  • cve — CVE-2021-23758
  • cve — CVE-2019-18935

Entities

UAT-10147 (threat_actor)SPECTRE (product)BadIIS (product)Quasar RAT (product)EfsPotato (product)Gh0stCringe (product)