Back to advisories

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UAT-10147, a Chinese-speaking cybercrime group, is actively targeting Windows and Linux web servers using AI-driven attack automation to exploit public vulnerabilities and deploy EDR-bypassing malware. Global targets include Brazil, Bolivia, China, Canada, and Vietnam, with objectives including SEO fraud, data theft, and server compromise.

HIGHAdvisoryAug 24, 2026
Action required
Hunt for suspicious web server activity: scan logs for exploitation attempts against public-facing apps, monitor for unexpected process execution with EDR evasion indicators, and check for persistence mechanisms targeting both Windows and Linux systems. Block known UAT-10147 IOCs immediately.
Affected products
SPECTREBadIISQuasar RATEfsPotatoGh0stCringe