The Chonkerton

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

tech

Cisco Talos reports it has identified a Chinese-speaking cybercrime group, tracked as UAT-10147, that is weaving agentic AI into attacks on Windows and Linux web servers around the world. The group has hit organizations in government, education, media, technology, and gaming, with affected servers in Brazil, Bolivia, China, Canada, and Vietnam. Per Talos, the actor uses AI-driven tooling across exploitation, reconnaissance, payload generation, and persistence — going beyond simple scripting help to iterative exploit refinement and adaptive troubleshooting. The group pairs that with open-source offensive frameworks like Metasploit and PentestGPT to automate intrusions and lower the expertise normally required for advanced post-compromise work. Talos says the group's target list held roughly one hundred seventy thousand URLs, split into seventeen files of about ten thousand each. The investigation began after an open directory on the actor's download server exposed the operation. Talos assesses with moderate-to-high confidence that UAT-10147 is part of an emerging class of financially motivated operators using agentic AI to industrialize offensive tradecraft — a shift from AI-assisted scripting toward semi-autonomous orchestration.

Source: https://blog.talosintelligence.com/uat-10147-chinese-spea...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton