Blog.Talosintelligence UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
Article Content
- •UAT-10147 targets vulnerable web servers globally, affecting sectors like government and technology.
- •The group uses AI-assisted tools, including the SPECTRE backdoor and BadIIS malware, for exploitation.
- •Approximately 170,000 URLs are on their target list, indicating a large-scale operation.
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations. Their activities include SEO fraud and data theft, with a target list of approximately 170,000 URLs. UAT-10147 utilizes various tools, including the custom backdoor SPECTRE and the BadIIS malware, to execute their attacks. The group has been observed exploiting multiple vulnerabilities, including CVE-2021-23758 and CVE-2022-27925, and employs sophisticated techniques for evasion and persistence. The current status indicates ongoing operations with significant implications for affected sectors such as government and technology.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track BadIIS and CVE-2019-16098 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…