Blog.Talosintelligence
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations. Their activities include SEO fraud and data theft, with a target list of approximately 170,000 URLs. UAT-10147 utilizes various tools, including the custom backdoor SPECTRE and the BadIIS malware, to execute their attacks. The group has been observed exploiting multiple vulnerabilities, including CVE-2021-23758 and CVE-2022-27925, and employs sophisticated techniques for evasion and persistence. The current status indicates ongoing operations with significant implications for affected sectors such as government and technology.
Key Points: • UAT-10147 targets vulnerable web servers globally, affecting sectors like government and technology. • The group uses AI-assisted tools, including the SPECTRE backdoor and BadIIS malware, for exploitation. • Approximately 170,000 URLs are on their target list, indicating a large-scale operation.