HackMyIP
← Back to News
2026-08-24 The Hacker News

UAT-10147 Hackers Use AI to Scale Attacks, Deploy SPECTRE Malware

AI ThreatsMalwareThreat Intel

Researchers at Cisco Talos have exposed a Chinese-speaking cybercrime operation dubbed UAT-10147 that is weaponizing artificial intelligence to automate large-scale intrusions against Windows and Linux web servers in the education, media, technology, and gaming sectors. The bulk of confirmed victims are located in Brazil, Bolivia, China, Canada, and Vietnam, though the group's internal target list—discovered in an exposed directory at 139.180.197[.]150—contains roughly 170,000 URLs split across 17 batches, with the United States, India, the United Kingdom, Germany, and the Netherlands appearing most frequently. You can verify suspicious infrastructure tied to campaigns like this using a WHOIS lookup.

What distinguishes UAT-10147 from conventional botnet crews is the systematic integration of AI tooling throughout the kill chain. The actor combines open-source offensive frameworks such as Metasploit, ysoserial, PentestGPT, and DeepAudit with AI assistants to refine exploits, troubleshoot logic, automate post-exploitation workflows, validate payloads, and generate operational documentation. Initial access is achieved by mass-exploiting known vulnerabilities in web applications and IIS servers to obtain remote code execution, after which an automated script installs SEO-fraud and data-theft malware. In some cases, a web shell is dropped to enable secondary payloads and persistent backdoors.

Once inside, UAT-10147 chains together EfsPotato for privilege escalation, configures Microsoft Defender exclusions, and erases initial artifacts to frustrate forensics. From there it deploys Quasar RAT via a deceptive scheduled task named "Google Chrome Start," the Gh0stCringe trojan, and a previously undocumented cross-platform implant called SPECTRE that includes EDR-bypass capabilities and a Linux rootkit component. The BadIIS malware is also installed to manipulate search engine results and harvest credentials. Operators are advised to audit exposed IIS and web-server instances with a port scanner and validate TLS configurations through an SSL/TLS checker, since the entry vector relies on publicly disclosed flaws rather than zero-days.

UAT-10147 illustrates a growing trend in which financially motivated actors adopt APT-style tradecraft and AI-assisted automation to industrialize attacks that were once manual and labor-intensive. Defenders should prioritize patch management for internet-facing web servers, monitor for unexpected Defender exclusions and scheduled-task creation, and review outbound traffic from web infrastructure. Individuals concerned about credential exposure from similar SEO-fraud and data-theft campaigns can run an email breach checker to determine whether their accounts have appeared in leaked datasets collected by malware families like BadIIS and Quasar RAT.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →