UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publicly disclosed vulnerabilities and AI-generated exploitation guidance, reconnaissance, and payload generation across Windows and Linux systems. They employ a two-pronged attack strategy, exploiting one-day vulnerabilities and leveraging AI to streamline their attacks, resulting in increased efficiency and reduced reliance on traditional expertise. The group targets sectors including government, education, media, technology, and gaming, and has been observed using tools like Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
