UAT-10147 uses AI to scale server attacks, deploys SPECTRE with EDR bypass

Cisco Talos disclosed Chinese-speaking cybercrime group UAT-10147 targeting Windows/Linux web servers globally, using AI tools like PentestGPT and DeepAudit to automate exploitation. The actor maintained a target list of ~170,000 URLs and deployed SPECTRE with EDR bypass and a Linux rootkit.
2 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Anthropic co-founder: chips, not algorithms, bottleneck AI
- Teachers targeted by sexualized AI deepfakes from students
- FDA promises generative AI medical device guidance
- ConvRot quantization method lands in llama-cpp-turboquant
- Hermes adds auxiliary review model to /review command