UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking adversary designated UAT-10147 is scaling server attacks by integrating agentic AI to automate vulnerability exploitation.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports from Cisco Talos Blog, The Hacker News, CyberInsider, gbhackers.com, and cyberpress.org detail a newly tracked threat activity cluster identified as UAT-10147. According to the coverage, this Chinese-speaking adversary is actively using artificial intelligence tools, specifically DeepSeek and Hermes Agent, to scale and automate cyberattacks targeting servers. Meanwhile, details published by The Hacker News indicate that the malicious operations involve deploying a tool known as SPECTRE, which features an endpoint detection and response, or EDR, bypass alongside a Linux rootkit. Additional reporting from gbhackers.com and cyberpress.org emphasizes the specific mechanics of the campaign, noting the integration of agentic AI into post-compromise operations. The coverage highlights how the adversary utilizes these advanced AI models to execute vulnerability exploitation autonomously.
Cisco Talos Blog first designated the threat actor as UAT-10147, framing the campaign around the use of agentic AI in post-compromise phases. The outlets uniformly point to the intersection of automated workflows, machine learning systems, and traditional backdoor installation techniques as the primary vectors of concern in this developing trend. This trend emerges as a significant development in threat intelligence regarding the operational use of publicly available or specialized large language models in malicious campaigns. While previous threat actors have experimented with AI for basic phishing or reconnaissance tasks, the coverage of UAT-10147 illustrates a shift toward agentic AI handling complex post-compromise maneuvers and autonomous exploitation. Outlets such as The Hacker News and Cisco Talos Blog provide technical context regarding the use of custom payloads like SPECTRE, showing that advanced evasion tactics continue to accompany automated tooling in targeted enterprise and server environments.
As the situation unfolds, security analysts and observers will monitor further disclosures regarding the full extent of the server targeting and the specific capabilities of the Hermes Agent integration. Coverage does not yet specify the total number of compromised entities beyond the broad scale reported, nor does it detail official remediation timelines or government responses. Future updates from the reporting outlets are expected to track the technical evolution of UAT-10147, the efficacy of the deployed Linux rootkits, and any additional infrastructure utilized by the Chinese-speaking threat actor in subsequent campaigns.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 45d ago.
Quick answers
Who is behind the AI-powered server attacks?
Coverage identifies a Chinese-speaking adversary designated as UAT-10147.
What AI tools are utilized in the campaign?
The threat actor uses DeepSeek and Hermes Agent to automate vulnerability exploitation and scale attacks.
What payloads are deployed during the operations?
The adversary deploys SPECTRE, which features an EDR bypass and a Linux rootkit.
Coverage (9)
- China-Linked Hacker Shows AI Capabilities in APAC Attack Dark Reading · 45d ago
- China’s Hackers Use AI Tech to Lift Attacks, Researchers Say Bloomberg.com · 45d ago
- Chinese hackers use DeepSeek AI to boost attacks Investing.com · 45d ago
- Chinese Hackers Use DeepSeek to Boost Attacks, Researchers Say Bloomberg.com · 45d ago
- Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks gbhackers.com · 45d ago
- Chinese hackers use AI to automate attacks on 170,000 servers CyberInsider · 45d ago
- Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation cyberpress.org · 45d ago
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Cisco Talos Blog · 45d ago
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Hacker News · 45d ago
Topics
Related trends
Meta’s Muse Is An Adorable Privacy And Security Dumpster Fire
Meta faces scrutiny following reports that its Muse AI agent handles privacy concerns and security vulnerabilities.
IBM & Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code
IBM and Red Hat have identified and remediated over 400 previously unknown vulnerabilities within popular open-source Java code using AI-powered tools.
How To Help Stop Spam Calls On iPhone And Android
New guides from the FCC and updated mobile features are empowering iPhone and Android users to combat the rise of robocalls and scam texts.
South Korea's Lee says AI appears to have been used in bank hacks
1 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
FBI says contractor failure led to hack of its jobs website
2 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Hackers obtain counterfeit TLS certificates for Google and other large services
10 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.