Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers — Threadlinqs Intelligence
As of 2026-08-21, Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers is a high-severity threat intel threat attributed to UAT-10147 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-2096 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: UAT-10147 · China · FINANCIAL
Cisco Talos identified UAT-10147, a Chinese-speaking financially motivated cybercrime group, using agentic AI systems to automate the exploitation of vulnerable internet-facing web servers running
Cisco Talos identified UAT-10147 (tracked since early 2026) as an emerging class of financially motivated intrusion operators integrating agentic AI into the full attack lifecycle. The group targets vulnerable internet-facing web servers globally, exploiting one-day vulnerabilities in Zimbra Collaboration Suite (CVE-2022-27925), AjaxPro .NET framework (CVE-2021-23758), Alibaba Nacos configuration service (CVE-2021-29441, CVE-2021-29442), and Progress Telerik UI for ASP.NET AJAX (CVE-2019-18935) for initial access.
On Windows IIS servers, the post-exploitation chain deploys a main script (back.txt/back.bat) via certutil that downloads privilege escalation tools (EfsPotato renamed as prcc1.rar), installs BadIIS malicious IIS modules for SEO fraud, deploys QuasarRAT disguised as svchosts.exe, and establishes persistent ASHX web shells. The group adds Windows Defender exclusions for IIS directories via PowerShell and registry, creates rogue local admin accounts, and establishes persistence through scheduled tasks named 'Google Chrome Start'.
On Linux servers, initial access is followed by web shell deployment and privilege escalation using multiple Linux kernel exploits including Dirty Pipe (CVE-2022-0847), Baron Samedit sudo heap overflow (CVE-2021-3156), watch_queue out-of-bounds write (CVE-2022-0995), and older LPE vulnerabilities. Post-exploitation implants include SPECTRE (a cross-platform C2 implant with a kernel-level rootkit named 'Specter'), NoodleRAT backdoor, and Meterpreter.
The group's most distinctive capability is its use of agentic AI across the full attack cycle, not merely for code generation. Talos recovered AI-generated Python scripts for diagnostics (check_paths.py), implant deployment (deploy_implant.py), web shell installation (deploy_shell.py), and recon/exfiltration (exfil.py). The AI assisted in troubleshooting failed exploits, generating a 9-section ASP.NET ViewState deserialization guide (covering MachineKey validation, ysoserial payload generation, OOB callback confirmation, and post-exploitation recon), and producing exploit validation workflows. The ASP.NET deserialization guide specifically documents that TypeConfuseDelegate gadget chain remains functional on .NET 4.8 despite public claims otherwise, and that HTTP 500 with InvalidCastException indicates successful exploitation (creating a monitoring blind spot).
The SPECTRE implant, a C-based cross-platform backdoor, represents the group's most sophisticated tool. On Windows, it features dual-layer anti-analysis (PEB hash walking for API resolution, per-string xorshift32 PRNG encryption), 45 commands (24 plaintext, 21 encrypted), three process injection methods (hollowing, APC EarlyBird, self-hollowing into RuntimeBroker.exe), credential theft via SAM hive dump, Chrome/Edge DPAPI theft, and Windows Credential Manager enumeration. It uses BYOVD (Bring Your Own Vulnerable Driver) via RTCore64.sys (CVE-2019-16098) and DBUtil_2_3.sys (CVE-2021-21551) to achieve kernel-level EDR bypass, neutralizing CrowdStrike Falcon, SentinelOne, and Microsoft Defender by unlinking PspCreateProcessNotifyRoutine, PspCreateThreadNotifyRoutine, and PspLoadImageNotifyRoutine callbacks. On Linux, SPECTRE is statically linked with an 8-factor anti-sandbox scoring engine, deploys a kernel rootkit disguised as acpi_pad.ko, uses ftrace to hook six syscall handlers, and achieves persistence via a systemd unit that loads before sysinit.target.
Infrastructure analysis reveals the group operates a download/C2 server at 139.180.197.150 (Vultr Tokyo, Japan, in a subnet with multiple confirmed Cobalt Strike and ShadowPad C2 servers), the domain adminapi.tippusoni.in for BadIIS distribution, and uses webhook.site as an exfiltration endpoint to blend with legitimate SaaS traffic. The group also leverages Nacos's configuration management service as an asynchronous exfiltration sink. AI tools recovered include DeepAudit (source code vulnerability scanning), PentestGPT (dynamic scanni
Weaknesses (CWE)
CWE-22, CWE-502, CWE-306, CWE-787, CWE-122, CWE-665
Target sectors: government administration, education, news - media, technology, gaming
Target regions: brazil, bolivia, china, canada, vietnam, india, thailand, japan
Timeline
- CISA adds CVE-2019-18935 (Telerik UI) to KEV catalog; UAT-10147 later observed weaponizing this vulnerability
- CVE-2021-29441 and CVE-2021-29442 Nacos vulnerabilities actively exploited in the wild, later weaponized by UAT-10147
- CVE-2022-0847 Dirty Pipe disclosed; UAT-10147 later observed using this Linux kernel LPE in their attack chain
- CISA adds CVE-2021-3156 (Baron Samedit sudo overflow) to KEV catalog
- CISA adds CVE-2022-0847 Dirty Pipe to Known Exploited Vulnerabilities catalog
- Mass exploitation of CVE-2022-27925 (Zimbra) begins in the wild, affecting over 1,000 ZCS instances; UAT-10147 weaponizes via Metasploit
- CISA adds CVE-2022-27925 to Known Exploited Vulnerabilities catalog following Volexity disclosure of mass exploitation
- CISA due date for federal agencies to patch Zimbra CVE-2022-27925 (still actively exploited as of 2026)
- Cisco Talos begins tracking UAT-10147 as a distinct intrusion set; group observed operating since at least late 2025
- Talos identifies UAT-10147 transitioning from AI-assisted scripting to semi-autonomous agentic AI orchestration of post-compromise operations
- SPECTRE cross-platform implant observed in UAT-10147 operations with BYOVD EDR bypass and Linux Specter rootkit
- Cisco Talos publishes comprehensive report detailing UAT-10147's agentic AI methodology and SPECTRE implant capabilities
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, CVE-2022-27925, CVE-2022-37042, CVE-2021-23758, CVE-2021-29441, CVE-2021-29442, CVE-2019-18935, CVE-2022-0847, CVE-2021-3156, CVE-2022-0995, CVE-2019-16098, T1190, T1059.001, T1059.003, T1059.004, T1203, T1106, T1505.003, T1505.002, T1053.005, T1136.001