National Cyber Warfare Foundation (NCWF)

UAT-10147


0 user ratings
2026-09-03 17:17:28
blscott

UAT-10147 is a newly documented, Chinese-speaking, financially motivated cybercrime intrusion set tracked by Cisco Talos. Talos publicly disclosed the group on August 20, 2026, after investigating compromised Windows and Linux web servers and discovering an operational-security failure that exposed attacker infrastructure, tooling, target lists, malware, and AI-generated attack documentation.

Talos assesses with moderate-to-high confidence that UAT-10147 represents an emerging class of financially motivated actors using agentic AI to automate offensive operations. Its principal known objectives are SEO fraud and data theft, rather than a currently established state-directed espionage mission.

Attribution and geographic associations

Attribute

Assessment

Designation

UAT-10147

Actor type

Cybercriminal / intrusion operator

Motivation

Financial

Language association

Chinese-speaking

State sponsorship

Not established

First publicly documented

August 20, 2026

Known activity

At least early 2026; SPECTRE observed from April 2026

Primary targets

Internet-facing Windows/IIS and Linux web servers

Objectives

SEO manipulation, traffic redirection, data theft, persistent server access

Distinguishing feature

Agentic-AI-assisted exploitation and post-compromise automation


Evidence supporting a Chinese-speaking association includes Chinese terminology in operational material, naming conventions, and artifacts recovered from attacker infrastructure. Talos also recovered an attacker-side Windows path containing the username “dajiba,” identified as pinyin for a Chinese expression. These artifacts support a linguistic association but do not establish the operators nationality or physical location.

Countries

Confirmed affected servers identified by Talos were located in:

Brazil, Bolivia, China, Canada, and Vietnam.

The much larger approximately 170,000-URL target list was geographically broader. Subsequent analysis identified the United States, India, United Kingdom, Germany, and Netherlands among the most heavily represented destinations in that list. A target appearing in the list does not necessarily mean it was successfully compromised.

Known attacks and campaigns

The currently documented activity appears to belong primarily to a broad 2026 mass web-server exploitation campaign rather than a collection of separately named historical operations.

UAT-10147 attacks internet-facing servers by exploiting known vulnerabilities to obtain RCE. Windows/IIS systems may subsequently receive BadIIS for SEO manipulation, QuasarRAT, Gh0stCringe or SPECTRE. Linux systems may receive web shells followed by privilege-escalation exploits and SPECTRE, NoodleRAT or Meterpreter.

A particularly important discovery was an attacker-controlled download server at 139.180.197[.]150. Its directory was unintentionally exposed, allowing Talos to recover tools, payloads, operational documentation and a target file containing approximately 170,000 URLs, subsequently divided into 17 files of roughly 10,000 targets each.

Exploited vulnerabilities

Known vulnerabilities associated with UAT-10147 operations include:

    • CVE-2022-27925 — Zimbra Collaboration Suite RCE

    • CVE-2021-23758 — AjaxPro deserialization RCE

    • CVE-2021-29441 / CVE-2021-29442 — Nacos arbitrary-code-execution chain

    • CVE-2019-18935 — Telerik UI for ASP.NET AJAX deserialization/file-upload exploitation

    • CVE-2022-0995 — Linux kernel privilege escalation

    • CVE-2021-3156 — sudo Baron Samedit

    • CVE-2015-5287 — ABRT privilege escalation

    • CVE-2015-3246 — libuser privilege escalation

    • CVE-2010-3904 — Linux RDS privilege escalation

    • CVE-2022-0847 — Dirty Pipe

Talos observed the actor using known one-day vulnerabilities rather than relying primarily on undisclosed zero-days.

Malware and offensive tooling

The groups observed arsenal includes SPECTRE, BadIIS, QuasarRAT, Gh0stCringe, NoodleRAT and Meterpreter, alongside offensive tools/frameworks such as Metasploit, PentestGPT, DeepAudit, ysoserial/ysoserial.net, EfsPotato and other Potato-family privilege-escalation techniques.

SPECTRE is particularly significant. It is a cross-platform C-based backdoor supporting Windows and Linux. Talos reports capabilities including C2, process injection, credential theft, anti-analysis functionality, Windows BYOVD-based EDR interference and a Linux kernel rootkit.

UAT-10147 has also attempted to deploy QuasarRAT for persistent access and used a custom Go loader to execute Gh0stCringe shellcode.

Agentic AI operations

The most distinctive element of UAT-10147 is the operational use of AI beyond ordinary malware coding.

Recovered material shows AI supporting:

exploit refinement → vulnerability/reconnaissance analysis → payload generation → exploitation → troubleshooting → validation → persistence → reconnaissance → exfiltration documentation.

Talos recovered AI-generated Python tooling including deployment diagnostics, SPECTRE deployment automation, an ASHX web-shell deployment utility (deploy_shell.py) and an exfiltration utility (exfil.py). The latter gathered IIS/webroot information and privilege data before transmitting it through HTTPS-based webhook infrastructure.

This makes UAT-10147 notable less because it invented fundamentally new exploitation primitives and more because it appears to have automated traditionally human-intensive post-exploitation tasks using agentic AI. 

Intelligence assessment

UAT-10147 currently appears to be a Chinese-speaking financially motivated intrusion operation rather than a confirmed Chinese state-sponsored APT. Its importance comes from the combination of mass exploitation, cross-platform persistence, BadIIS monetization, sophisticated SPECTRE capabilities and unusually extensive use of AI for operational automation.

The roughly 170,000-target dataset also suggests an industrialized exploitation model: identify exposed infrastructure at scale, automatically test known vulnerabilities, validate successful compromise, establish persistence and then monetize accessible servers through SEO manipulation and/or data theft.

The highest-value hunting pivots at present are therefore 139.180.197[.]150, the adminapi.tippusoni[.]in infrastructure, SPECTRE/BadIIS artifacts, unexpected IIS Defender exclusions, Google Chrome Start scheduled tasks, ASHX web shells, Potato-family privilege escalation, and exploitation attempts against the documented Zimbra/Nacos/Telerik/AjaxPro vulnerabilities.

Cisco Talos UAT-10147 investigation

Cisco Talos SPECTRE analysis

Cisco Talos UAT-10147 IOC repository

Cisco Talos SPECTRE IOC repository



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.