UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos tracks UAT-10147, a Chinese-speaking cybercrime group exploiting vulnerable web servers and using agentic AI in post-compromise operations.
Cisco Talos identified a Chinese-speaking cybercrime group tracked as UAT-10147 that targets a wide range of vulnerable web servers. The report maps affected countries and analyzes the impact of BadIIS infections on compromised servers. It also documents the attack chain and emerging use of agentic AI during post-compromise activities.
- Targets a wide range of vulnerable web servers across multiple countries
- Uses agentic AI tools during post-compromise operations
- Deploys BadIIS infections on compromised servers
- Tracked as UAT-10147, an unattributed threat designation
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
This source does not provide full text. Read it at blog.talosintelligence.com.