UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking adversary designated UAT-10147 is scaling server attacks by integrating agentic AI to automate vulnerability exploitation.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports from Cisco Talos Blog, The Hacker News, CyberInsider, gbhackers.com, and cyberpress.org detail a newly tracked threat activity cluster identified as UAT-10147. According to the coverage, this Chinese-speaking adversary is actively using artificial intelligence tools, specifically DeepSeek and Hermes Agent, to scale and automate cyberattacks targeting servers. Meanwhile, details published by The Hacker News indicate that the malicious operations involve deploying a tool known as SPECTRE, which features an endpoint detection and response, or EDR, bypass alongside a Linux rootkit. Additional reporting from gbhackers.com and cyberpress.org emphasizes the specific mechanics of the campaign, noting the integration of agentic AI into post-compromise operations. The coverage highlights how the adversary utilizes these advanced AI models to execute vulnerability exploitation autonomously.
Cisco Talos Blog first designated the threat actor as UAT-10147, framing the campaign around the use of agentic AI in post-compromise phases. The outlets uniformly point to the intersection of automated workflows, machine learning systems, and traditional backdoor installation techniques as the primary vectors of concern in this developing trend. This trend emerges as a significant development in threat intelligence regarding the operational use of publicly available or specialized large language models in malicious campaigns. While previous threat actors have experimented with AI for basic phishing or reconnaissance tasks, the coverage of UAT-10147 illustrates a shift toward agentic AI handling complex post-compromise maneuvers and autonomous exploitation. Outlets such as The Hacker News and Cisco Talos Blog provide technical context regarding the use of custom payloads like SPECTRE, showing that advanced evasion tactics continue to accompany automated tooling in targeted enterprise and server environments.
As the situation unfolds, security analysts and observers will monitor further disclosures regarding the full extent of the server targeting and the specific capabilities of the Hermes Agent integration. Coverage does not yet specify the total number of compromised entities beyond the broad scale reported, nor does it detail official remediation timelines or government responses. Future updates from the reporting outlets are expected to track the technical evolution of UAT-10147, the efficacy of the deployed Linux rootkits, and any additional infrastructure utilized by the Chinese-speaking threat actor in subsequent campaigns.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 1h ago.
Quick answers
Who is behind the AI-powered server attacks?
Coverage identifies a Chinese-speaking adversary designated as UAT-10147.
What AI tools are utilized in the campaign?
The threat actor uses DeepSeek and Hermes Agent to automate vulnerability exploitation and scale attacks.
What payloads are deployed during the operations?
The adversary deploys SPECTRE, which features an EDR bypass and a Linux rootkit.
Coverage (5)
- Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks gbhackers.com · 5h ago
- Chinese hackers use AI to automate attacks on 170,000 servers CyberInsider · 5h ago
- Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation cyberpress.org · 5h ago
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Cisco Talos Blog · 5h ago
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Hacker News · 5h ago
Topics
Related trends
Hackers infect Android car head units with proxy botnet malware
Cyber attackers are targeting Android-based automotive head units to build a proxy botnet and conduct ad fraud through built-in system updaters.
AliExpress was silently running audio in your browser to fingerprint and track your device
Researchers discover that AliExpress and Alibaba covertly tracked users' devices by running silent audio in browsers.
Small UK power generator shut down after cyberattack linked to Iran: Telegraph
A cyberattack linked to Iran has forced the shutdown of a small UK power generator, exposing critical vulnerabilities in Western infrastructure.
Iranian hackers carry out unprecedented attack on UK’s power network
Iranian-linked hackers have launched an unprecedented cyber attack on the UK power network, causing a four-day shutdown of a power plant.
If you're not using AI to attack your own systems, your adversaries will
Cybersecurity experts warn that organizations must use AI for offensive self-testing to counter the increasing speed and scale of AI-assisted attacks.
Do you need a VPN? And which is best for you?
A growing debate over digital privacy centers on whether users actually need a VPN and the security risks associated with free service providers.