UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks

UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks

First seen 20 Aug 2026, 10:22 UTC Blog.Talosintelligencenvd.nist.gov 89% similarity 75.0

Article Content

Browse articles
ThreatCluster

In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations. Their activities include SEO fraud and data theft, with a target list of approximately 170,000 URLs. UAT-10147 utilizes various tools, including the custom backdoor SPECTRE and the BadIIS malware, to execute their attacks. The group has been observed exploiting multiple vulnerabilities, including CVE-2021-23758 and CVE-2022-27925, and employs sophisticated techniques for evasion and persistence. The current status indicates ongoing operations with significant implications for affected sectors such as government and technology.

Key Points: • UAT-10147 targets vulnerable web servers globally, affecting sectors like government and technology. • The group uses AI-assisted tools, including the SPECTRE backdoor and BadIIS malware, for exploitation. • Approximately 170,000 URLs are on their target list, indicating a large-scale operation.

ThreatCluster AI How this analysis works

Timeline

2019-09-11
CVE-2019-16098 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-12-11
CVE-2019-18935 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-04-27
CVE-2021-29442 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-05-04
CVE-2021-21551 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-03
CVE-2021-23758 published
A vulnerability in web servers that UAT-10147 exploits was disclosed.
Blog.Talosintelligence
2022-04-20
CVE-2022-27925 published
A critical vulnerability affecting web servers was published, later exploited by UAT-10147.
Blog.Talosintelligence
2022-08-11
CVE-2022-27925 added to CISA KEV
CISA added this vulnerability to its Known Exploited Vulnerabilities list, indicating active exploitation.
Blog.Talosintelligence
2026-06-25
CVE-2021-29441 first public PoC
A proof of concept for this vulnerability was released, potentially aiding UAT-10147's operations.
Blog.Talosintelligence
2026-08-20
UAT-10147 campaign detailed
Cisco Talos published findings on UAT-10147's use of AI in cybercrime operations, revealing extensive targeting.
Blog.Talosintelligence

Community

Browse all →