Cisco Talos has been tracking a Chinese-speaking criminal group, UAT-10147, that pairs off-the-shelf attack tools with AI helpers to compromise Windows and Linux web servers in the education, media, technology, and gaming sectors. Talos says most of the victims are based in Brazil, Bolivia, China, Canada, and Vietnam.
The researchers found the group’s infrastructure exposed an open directory holding a list of roughly 170,000 target URLs, split into 17 files of about 10,000 each for processing. Access typically starts with known public flaws – including CVE-2022-27925 in Zimbra and CVE-2019-18935 in Telerik UI for ASP.NET AJAX – after which an automated script installs malware for SEO fraud and data theft, dropping web shells, BadIIS, Gh0stCringe, and Quasar RAT.
The centerpiece is SPECTRE, a cross-platform backdoor written in C that ships with 45 commands on Windows and 29 on Linux. The Windows build neutralizes endpoint detection by loading vulnerable drivers, RTCore64.sys and DBUtil_2_3.sys, to detach EDR kernel callbacks and blind CrowdStrike Falcon, SentinelOne, and Microsoft Defender. A separate Linux variant includes a kernel rootkit named Specter. Talos dates the backdoor’s first use to April 2026.
AI shows up throughout the operation. The group uses it to refine exploits, validate payloads, and automate post-exploitation steps, and its servers run PentestGPT plus an AI scanner called DeepAudit. Exfiltrated data flows through a Nacos cloud configuration service, blending in with normal administrative traffic.
