ZeroHour
Cisco Talospublished ()ingested Joey Chen

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

mediumThreat actor exploited in the wildimportance 55
AI summary · glm-5.3-flash

Cisco Talos tracks UAT-10147, a Chinese-speaking cybercrime group exploiting vulnerable web servers and using agentic AI in post-compromise operations.

Cisco Talos identified a Chinese-speaking cybercrime group tracked as UAT-10147 that targets a wide range of vulnerable web servers. The report maps affected countries and analyzes the impact of BadIIS infections on compromised servers. It also documents the attack chain and emerging use of agentic AI during post-compromise activities.

  • Targets a wide range of vulnerable web servers across multiple countries
  • Uses agentic AI tools during post-compromise operations
  • Deploys BadIIS infections on compromised servers
  • Tracked as UAT-10147, an unattributed threat designation
ProductsBadIIS
Threat actorsUAT-10147
MalwareBadIIS
Full article

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

This source does not provide full text. Read it at blog.talosintelligence.com.