# UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

> **Open Intelligence Dossier** · First detected: 2026-08-24 12:07 UTC · Category: Technology

## Executive Summary
A Chinese-speaking adversary designated UAT-10147 is scaling server attacks by integrating agentic AI to automate vulnerability exploitation.

## Intelligence Brief
Recent reports from Cisco Talos Blog, The Hacker News, CyberInsider, gbhackers.com, and cyberpress.org detail a newly tracked threat activity cluster identified as UAT-10147. According to the coverage, this Chinese-speaking adversary is actively using artificial intelligence tools, specifically DeepSeek and Hermes Agent, to scale and automate cyberattacks targeting servers. Meanwhile, details published by The Hacker News indicate that the malicious operations involve deploying a tool known as SPECTRE, which features an endpoint detection and response, or EDR, bypass alongside a Linux rootkit. Additional reporting from gbhackers.com and cyberpress.org emphasizes the specific mechanics of the campaign, noting the integration of agentic AI into post-compromise operations. The coverage highlights how the adversary utilizes these advanced AI models to execute vulnerability exploitation autonomously.


Cisco Talos Blog first designated the threat actor as UAT-10147, framing the campaign around the use of agentic AI in post-compromise phases. The outlets uniformly point to the intersection of automated workflows, machine learning systems, and traditional backdoor installation techniques as the primary vectors of concern in this developing trend. This trend emerges as a significant development in threat intelligence regarding the operational use of publicly available or specialized large language models in malicious campaigns. While previous threat actors have experimented with AI for basic phishing or reconnaissance tasks, the coverage of UAT-10147 illustrates a shift toward agentic AI handling complex post-compromise maneuvers and autonomous exploitation. Outlets such as The Hacker News and Cisco Talos Blog provide technical context regarding the use of custom payloads like SPECTRE, showing that advanced evasion tactics continue to accompany automated tooling in targeted enterprise and server environments.


As the situation unfolds, security analysts and observers will monitor further disclosures regarding the full extent of the server targeting and the specific capabilities of the Hermes Agent integration. Coverage does not yet specify the total number of compromised entities beyond the broad scale reported, nor does it detail official remediation timelines or government responses. Future updates from the reporting outlets are expected to track the technical evolution of UAT-10147, the efficacy of the deployed Linux rootkits, and any additional infrastructure utilized by the Chinese-speaking threat actor in subsequent campaigns.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| Dark Reading | China-Linked Hacker Shows AI Capabilities in APAC Attack | [Source Link](https://news.google.com/rss/articles/CBMipAFBVV95cUxOOHlVUlBxOTljdW96SkpSdUIyU0V0TmNaZUw1b181bktkbmFaS3d2X3RyVlc3eTN2YnhWRkFOTVdWRDFKQ0EyekZPRHF5d2VQTnlJTG1MTU5xRXE4T2Y4LVdwanI0RDA2V1BqUVh1VlBkN182UmlCZ3d5TGYtM2xJbVo4Mkl1d0dFd2Y3STQ0cGJSbHV0SFljRWJxTWV3bGZJSldkMg?oc=5) |
| Bloomberg.com | China’s Hackers Use AI Tech to Lift Attacks, Researchers Say | [Source Link](https://news.google.com/rss/articles/CBMivgFBVV95cUxOZEpqTmlyY1RnNmtHTEJVXzBnb0IyaU9FdHdQbnlOSTI1cVg3YW1rbzdrU2NyWjR6YmowOG1pemFmSnZaZ1lMY24tWUIzQTRWMUVDUmFFeVVncWVjM3p1VFAxWGVjTzkyTXRiMURPYTlFU0FQV19UQlU4a01JZU8tUmt4c29oNUdRUUQ3WVVUUkNWRjRkdU0xSG52VWI2UDVQQ3YxQXA5Qm9XSGZUblozcFVETEhHQ0lBSW5ZcExn?oc=5) |
| Investing.com | Chinese hackers use DeepSeek AI to boost attacks | [Source Link](https://news.google.com/rss/articles/CBMiqAFBVV95cUxOSGg3WTE3TGdhd01MME1ROXYtY2lxbGJuSjJtT3Z2Zi1oZlcwMXg3NFZHSkU5MGE3bHlYSjJZSHJ1Q2Vla0pRcWw4d3dLaEhTV1VlV2g5Ukc2Wk56WHJCN2lBS3Vtd2h6WXF0dm5wckFEUjZveWpwZnYxVW9kM1FvYzBMNnNlX0NaWFVmbU4zTVd0enFwdnFleWJpX0JwUnU1NmdWdWNveFQ?oc=5) |
| Bloomberg.com | Chinese Hackers Use DeepSeek to Boost Attacks, Researchers Say | [Source Link](https://news.google.com/rss/articles/CBMisgFBVV95cUxNUzhVcmx3UnRJMGN0SmJRclJnZTlrWnh2c0t4Nm5kQ1g4YWNvQVJScXVTZjNldm03VmdLdHp2Y1p6d3pJZUZoM01tQlBENlFMRGJQcm9hMEI5LVJtQ29yOGdaUnFxekg5X3BCXzdPNWJxQlpPclNiT3VYaDVqY2dCWDVTbGRHWlpoSTk3c2FPWHZPWmxtNXIzNUNLOC1VWGhtQTlxeEk1YWRxWHZ4dGhkMkJn?oc=5) |
| gbhackers.com | Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks | [Source Link](https://news.google.com/rss/articles/CBMickFVX3lxTE80ZlNBSTdXbDJsa2N6NkZPOTZBcHlUMUxzazNXVFg4SWFDTkYzUFZXN1lGc0h2MENVSXM5b3hXcjYyNE5hX1pnd3VOVlk3S0poZnlVT2VNU1AzQTVRcEhQVWhKS1ZqQ1JnZk9CZlF2cWlNUdIBd0FVX3lxTE9QLTFMQWxmRTcyVWFOSVk1a0FPclpnSUZieFRWeTRiUVkzOWo3R0VrbXVSbU9FWmticFFZdEZ2Z1oxc1JGMlZJTDJFNjVsU1k5Vl9oZnNBbWhudUVPZHJGeUtWNDIyNzVma1BUc0VNVUtGSFlVdWNJ?oc=5) |
| CyberInsider | Chinese hackers use AI to automate attacks on 170,000 servers | [Source Link](https://news.google.com/rss/articles/CBMijwFBVV95cUxOUjZFQUY5cUJjcGlnUUZWREpWTXcwd0xzN2l0OEJWM2ZKV3ZfUzdCenZTaDNzM2MtNV82UlduUVd0eHhxYjNYX2FYLW9Bc0VQNFNaS3JBazUyZXhpcXZ2MlJuZjlBS2dNRjYtOHdmS09mNUJydFdpNkwyWURrOGZDVXBWNE1yQVZ3V0ZlY3hXYw?oc=5) |
| cyberpress.org | Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation | [Source Link](https://news.google.com/rss/articles/CBMiZkFVX3lxTE5HV0IyQ3RZSm50eVhPY1lraTJTV1lrZ3ctZkg1ZWdvcE1yTV9WRmpTRlhFUkxPSlg4V3Vha0dvazBJNjVnTm5ZWGU0Rk9fUTMycTRQTzJPRjdHWDExVXZJeU51UTB2Z9IBZkFVX3lxTE5HV0IyQ3RZSm50eVhPY1lraTJTV1lrZ3ctZkg1ZWdvcE1yTV9WRmpTRlhFUkxPSlg4V3Vha0dvazBJNjVnTm5ZWGU0Rk9fUTMycTRQTzJPRjdHWDExVXZJeU51UTB2Zw?oc=5) |
| Cisco Talos Blog | UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations | [Source Link](https://news.google.com/rss/articles/CBMixAFBVV95cUxQQURFUDZBa2JkY1ZYYWpfLXl4RHpJT05ESE53elFZZV93Z2ZQQjRKanEyUGZIaW9yYVg1UlZTUEJKTm1MblpGQzVFVFZtdlVITndVdUdZZmpleE5JV3REeUFCdXJUWVBvbGdwT0ZrZnJlQ1VBcEk5eTgydUg0SFY1ck9WUUFuWmthNm11Y2xkd1BxNEw3WTJtOXhmdkhtNGNiMjhDckNSRDBGbEhoMXFPWUpSd01USXJ6c3lYbzRiWjBGNzBQ?oc=5) |
| The Hacker News | UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit | [Source Link](https://news.google.com/rss/articles/CBMifEFVX3lxTE5BYk1adFZSeVh5YlhkeUVYY0V6azlsREdUaEZyQzdyVW1Bak80c1lxVzRQMlcxWGVYWUxkTmt1S0dscnZxSXY0VWxVbGlYUGptUWpSNUQyNV93MlRIaGFjSk1acERKLXhCc0luRVhZaVBVR29Sb2pWUnlsb04?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-08-24/uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and*
