Chinese Cybercrime Group Utilises AI to Automate Attacks on Servers


|

Chinese Cybercrime Group Utilises AI to Automate Attacks on Servers
Chinese Cybercrime Group Utilises AI to Automate Attacks on Servers
A Chinese-speaking hacker group leverages AI to automate attacks on 170,000 vulnerable servers globally, targeting data theft and SEO fraud.

In early 2026, a cybercrime group known as UAT-10147, identified by Cisco Talos, began using artificial intelligence to automate attacks on internet-facing Windows and Linux web servers worldwide. This group has been linked to various criminal activities, including data theft and search engine optimisation (SEO) fraud.

Attack Overview

The UAT-10147 group targets a wide range of organisations, including government agencies, universities, media outlets, technology firms, and gaming companies across several countries, including Brazil, Bolivia, China, Canada, and Vietnam. By exploiting vulnerabilities in widely used software products, such as Zimbra and Telerik UI, the group launches automated attacks on approximately 170,000 identified servers.

Talos researchers, including Joey Chen, reported that the campaign was uncovered when investigators observed a compromised server communicating with a download server. An operational mistake left the server's directory publicly accessible, revealing malware, scripts, tools, and lists of targeted URLs.

Tools and Techniques

UAT-10147 employs a sophisticated range of tools, including publicly available exploits and custom malware, to automate their attacks. They utilise a powerful backdoor known as SPECTRE, which is specifically designed for both Windows and Linux systems. The Windows variant features numerous commands, including commands for credential theft, keylogging, and even processes that can manipulate kernel callbacks to evade detection by endpoint security solutions.

On the Linux side, the group uses web shells and a custom-developed rootkit known as Specter, which hides itself and other processes while maintaining elevated privileges. Researchers believe that elements of the Linux rootkit may have been constructed with AI assistance due to the methodical and structured comments found in the source code.

Another notable aspect of this threat group is the integration of AI into their post-compromise operations. This includes the use of AI-generated documentation and scripts intended for exploit validation and troubleshooting, indicating a shift towards more sophisticated and semi-automated attack methodologies.

Threat Mitigation

Administrators of internet-facing servers are advised to promptly patch existing vulnerabilities and implement security measures, such as rotating ASP.NET MachineKeys and limiting administrative access. Monitoring for unexpected Microsoft Defender exclusions and suspicious scheduled tasks can aid in identifying compromised servers before attackers establish persistent access.

The presence of AI in cybercrime has significant implications for global cybersecurity. As cybercriminals develop increasingly automated and sophisticated methods of attack, traditional defensive strategies may need to evolve to counter these emerging threats.

As this situation develops, organisations are encouraged to stay vigilant and prioritise robust cybersecurity measures to protect sensitive data against the growing threat of AI-enhanced cybercrime activities.

Kerala Initiates Probe into 2006 Suicide Case Involving CEC
Kerala Initiates Probe into 2006 Suicide Case Involving CEC
The Kerala government has ordered a vigilance investigation following a 2006 suicide incident linked to Chief Election Commissioner Gyanesh Kumar.
|
Extradition of Sheikh Hasina Feasible, Says Indian High Commissioner
Extradition of Sheikh Hasina Feasible, Says Indian High Commissioner
Indian High Commissioner to Bangladesh claims Sheikh Hasina's extradition is possible through a structured process, fostering bilateral cooperation.
|
Punjabi Makeup Artist Mad Sandhu Shot Dead in Amritsar
Punjabi Makeup Artist Mad Sandhu Shot Dead in Amritsar
Influencer and makeup artist Mad Sandhu was fatally shot in Amritsar. Police have launched an investigation into the incident.
|
India Achieves Fourth Place at Asian Games 2026 Through Late Success
India Achieves Fourth Place at Asian Games 2026 Through Late Success
India secured fourth place in the Asian Games 2026 medals tally, boosted by impressive performances in key sports such as boxing and archery.
|
Pakistan Requests Indian Diplomat's Presence Over Border Incident
Pakistan Requests Indian Diplomat's Presence Over Border Incident
Pakistan has summoned an Indian diplomat to protest the alleged killing of two citizens by the Border Security Force.
|