[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-li-mt7js2e3":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"317d71f1-558a-43b7-8649-5d58e6452fc5","UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit","uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-li-mt7js2e3","UAT-10147, a Chinese-speaking cybercrime group, is actively targeting Windows and Linux web servers using AI-driven attack automation to exploit public vulnerabilities and deploy EDR-bypassing malware. Global targets include Brazil, Bolivia, China, Canada, and Vietnam, with objectives including SEO fraud, data theft, and server compromise.","high","advisory",[],[13,14,15,16,17],"SPECTRE","BadIIS","Quasar RAT","EfsPotato","Gh0stCringe","Hunt for suspicious web server activity: scan logs for exploitation attempts against public-facing apps, monitor for unexpected process execution with EDR evasion indicators, and check for persistence mechanisms targeting both Windows and Linux systems. Block known UAT-10147 IOCs immediately.",[20],"12d5d4ab-663e-4954-8b11-2eeffe0d26ad",null,[23],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fuat-10147-uses-ai-to-scale-server.html","active","2026-08-26T18:06:15.269+00:00","2026-08-24T18:06:23.323743+00:00","2026-08-24T18:08:22.405714+00:00",[29],{"id":20,"title":6,"url":23}]