Trusted Design

Chinese-speaking adversary integrates agentic AI into post-compromise operations

概要

A Chinese-speaking cybercrime group designated UAT-10147 has been identified targeting Windows and Linux web servers worldwide, affecting organizations across government, education, media, technology, and gaming sectors. The adversary exploits publicly disclosed vulnerabilities to achieve initial access at scale, then deploys AI-driven tooling throughout exploitation, reconnaissance, payload generation, validation, and persistence workflows. The operation leverages open-source offensive frameworks including Metasploit, ysoserial, PentestGPT, and DeepAudit to automate intrusion operations. UAT-10147 demonstrates an emerging capability of integrating semi-autonomous AI systems for iterative exploit refinement, adaptive troubleshooting, and operational documentation generation. Targeting includes approximately 170,000 URLs across multiple countries, with post-compromise activities involving deployment of various implants, BadIIS installations, and SEO fraud operations.

Created: 2026-08-20

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る