UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking cybercrime group dubbed UAT-10147 has been targeting Windows and Linux web servers globally, using AI-powered tools to scale server attacks and deploy malware for SEO fraud and data theft.
Intelligence analysis by Llama

UAT-10147, a Chinese-speaking cybercrime group, has been targeting Windows and Linux web servers globally, using AI-powered tools to scale server attacks and deploy malware for SEO fraud and data theft. The group has been identified as conducting search engine optimization (SEO) fraud and data theft, integrating AI-powered tools at various phases of the attack cycle to facilitate expl…
UAT-10147 is a group of hackers using AI tools to attack websites and steal data. They use a combination of open-source tools and AI-powered frameworks to automate their attacks and make it harder to detect them. The group has been targeting Windows and Linux web servers globally, using a mixture of exploits and malware to gain access and steal data.
Analysis
UAT-10147: A Threat Actor Leveraging AI-Powered Tools to Scale Server Attacks and Deploy Malware for SEO Fraud and Data Theft
UAT-10147, a Chinese-speaking cybercrime group, has been identified as conducting search engine optimization (SEO) fraud and data theft, integrating AI-powered tools at various phases of the attack cycle to facilitate exploitation, reconnaissance, payload generation, validation, and persistence. The group has been targeting Windows and Linux web servers globally, using a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence.
The actor employed a batch script that employs certutil to download a privilege escalation tool (EfsPotato), a secondary batch script, and Quasar RAT from a remote server (adminapi.tippusoni[in]). Using EfsPotato to gain elevated system privileges, configure Microsoft Defender exclusions, deleting initial payloads to cover its tracks and thwart forensic analysis, deploying follow-on implants like Gh0stCringe and a previously unreported cross-platform implant dubbed SPECTRE, abusing the elevated privileges to download a third batch script, which then installs BadIIS.
Interestingly, the core BadIIS malware is the same specific variant that's known to operate under a malware-as-a-service (MaaS) model and is used by multiple Chinese-speaking cybercrime groups. The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847. Once root-level access is unlocked, the threat actor has been observed deploying multiple backdoors like Noodle RAT (a variant of Gh0st RAT and Rekoobe), SPECTRE, and Meterpreter to enable outbound connections to remote command-and-control (C2) infrastructure.
A notable aspect of UAT-10147's tradecraft concerns an AI-driven framework called DeepAudit for vulnerability scanning. Talos said it found no evidence of the threat actor exploiting vulnerabilities discovered by the tool in victim environments, although it was left accessible on the management server. This has raised the possibility that the attackers are planning on using DeepAudit to identify vulnerabilities within target environments. Conversely, it's also likely that it could be used to improve their own defensive posture by proactively auditing their own infrastructure and tooling to prevent potential exposure and compromise by other threat actors.
UAT-10147 has also been found to install PentestGPT, an open-source autonomous pentesting framework, on their C2 server to scan web servers and execute relevant proof-of-concept exploits. In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands. Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects: making use of the badsecrets library comprising publicly known or leaked ASP.NET MachineKey configurations, checks the ViewState's integrity, and executes the payload.
Key points
- UAT-10147 is a Chinese-speaking cybercrime group targeting Windows and Linux web servers globally.
- The group uses AI-powered tools to scale server attacks and deploy malware for SEO fraud and data theft.
- UAT-10147 has been identified as conducting search engine optimization (SEO) fraud and data theft, integrating AI-powered tools at various phases of the attack cycle to facilitate exploitation, reconnaissance, payload generation, validation, and persistence.
- The group has been using a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence.
- UAT-10147 has been found to install PentestGPT, an open-source autonomous pentesting framework, on their C2 server to scan web servers and execute relevant proof-of-concept exploits.
The use of AI-powered tools by UAT-10147 highlights the growing threat of AI-driven cybercrime, but it also presents an opportunity for cybersecurity measures to be enhanced to protect against such attacks. By understanding the tactics and techniques used by UAT-10147, cybersecurity professionals can develop more effective countermeasures to prevent and detect AI-driven cyber attacks.
The use of AI-powered tools by UAT-10147 also raises concerns about the potential for AI-driven cybercrime to become more sophisticated and difficult to detect. If left unchecked, UAT-10147's tactics and techniques could be adopted by other threat actors, leading to a more complex and challenging cybersecurity landscape.


