
Cisco Talos has published a detailed profile of UAT-10147, a Chinese-speaking cybercrime group that has been compromising Windows and Linux web servers across the education, media, technology, and gaming sectors globally. The group’s primary targets are in Brazil, Bolivia, China, Canada, and Vietnam, though its target list — found on an exposed management server — contains roughly 170,000 URLs spanning the U.S., India, the U.K., Germany, and the Netherlands. What sets UAT-10147 apart is its heavy integration of AI tools across the entire attack lifecycle: it uses PentestGPT for automated exploitation, a custom scanner called DeepAudit for vulnerability discovery, and AI-generated Python scripts for post-exploitation tasks including payload delivery, web shell deployment, and data exfiltration that blends with legitimate SaaS traffic.
The campaign’s most technically significant payload is SPECTRE, a new cross-platform backdoor written in C that Talos describes as a major evolution in commodity intrusion tooling. The Windows variant supports 45 commands and uses the bring-your-own-vulnerable-driver (BYOVD) technique — loading signed but flawed drivers from MSI (CVE-2019-16098) and Dell (CVE-2021-21551) — to write directly to the kernel and unlink EDR callbacks, rendering security products including CrowdStrike Falcon, SentinelOne, and Microsoft Defender completely blind to new process activity. The Linux variant deploys a kernel-level rootkit named Specter that persists across reboots. Both versions include anti-sandbox and anti-analysis checks that cause the implant to self-terminate if the environment looks like a research system. UAT-10147 gained initial access by exploiting known vulnerabilities in Zimbra, Telerik UI for ASP.NET, AjaxPro, and Alibaba Nacos before dropping SPECTRE alongside older backdoors including Noodle RAT and Meterpreter.
