Chinese-Speaking Group UAT-10147 Uses Agentic AI to Scale Global Server Attacks
The group leverages AI automation and a cross-platform implant called SPECTRE to compromise Windows and Linux servers.
A Chinese-speaking cybercrime group identified as UAT-10147 is conducting a global campaign targeting Windows and Linux web servers. The group integrates agentic AI into its core workflow to automate and scale reconnaissance, exploitation, and the generation of payloads, marking a significant shift in how server-side compromises are executed.
This automation allows UAT-10147 to identify and attack vulnerabilities more efficiently than traditional manual methods. The group's primary targets are concentrated in Brazil, Bolivia, China, Canada, and Vietnam, with a specific focus on the government, education, media, technology, and gaming sectors.
Advanced Evasion Tactics
Central to the group's success is the deployment of a cross-platform implant known as SPECTRE. This tool is designed for stealth and persistence across different operating systems. On Linux systems, SPECTRE utilizes a rootkit to hide its presence from administrators. For Windows environments, the implant employs "Bring Your Own Vulnerable Driver" (BYOVD) techniques to bypass Endpoint Detection and Response (EDR) security software, effectively blinding security tools to the group's activity.
The Impact of AI Integration
The integration of agentic AI represents a significant escalation in the efficiency and stealth of server-side compromises. By automating the early stages of the attack chain, UAT-10147 can cast a wider net and execute attacks at a volume and speed that would typically require a much larger team of human operators. When combined with the EDR bypass capabilities of SPECTRE, the result is a highly scalable operation that can penetrate hardened environments while remaining undetected for extended periods.
Industry Implications
This campaign highlights a growing trend where cybercriminals move beyond simple AI-generated phishing emails toward using AI for active exploitation and operational scaling. For organizations in the targeted sectors—particularly government and technology—the threat is no longer just about the sophistication of the malware, but the speed at which the attack surface is scanned and exploited. The use of BYOVD techniques further underscores the fragility of trust-based security models in Windows environments.
Future Outlook
Security researchers continue to monitor UAT-10147 as they refine their AI-driven workflows. The discovery of these methods followed the identification of an exposed resource that revealed the group's operational blueprints. Defenders are now urged to monitor for unauthorized driver loads and unusual rootkit-like behavior on Linux servers to detect potential SPECTRE infections. As AI tools become more accessible, the window between vulnerability discovery and exploitation will likely continue to shrink, requiring more proactive, AI-driven defense mechanisms to counter these automated threats.