news.mlab.sh
Back to the feed
threat-intel

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

High
Image: Cisco Talos
Summary

Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publicly disclosed vulnerabilities and AI-generated exploitation guidance, reconnaissance, and payload generation across Windows and Linux systems. They employ a two-pronged attack strategy, exploiting one-day vulnerabilities and leveraging AI to streamline their attacks, resulting in increased efficiency and reduced reliance on traditional expertise. The group targets sectors including government, education, media, technology, and gaming, and has been observed using tools like Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits.

Read the full article at Cisco Talos

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.