News › security
By Zayden R., August 24, 2026
Cybersecurity researchers have uncovered UAT-10147, a Chinese-speaking group using AI to target Windows and Linux servers globally. This development raises concerns due to its potential to automate and scale cyberattacks.
Cybersecurity researchers have disclosed the activities of UAT-10147, a Chinese-speaking cybercrime group targeting both Windows and Linux servers around the world. This group leverages artificial intelligence (AI) to enhance its attack capabilities, making it a significant concern for sectors such as education, media, technology, and gaming. The majority of targets are located in Brazil, Bolivia, China, Canada, and Vietnam.
The discovery was made after an open directory at IP address 139.180.197[.]150 was found communicating with compromised machines. The group uses a mix of publicly known vulnerabilities and open-source offensive frameworks like Metasploit, ysoserial, PentestGPT, and DeepAudit, alongside multiple privilege escalation exploits. This combination allows them to automate intrusion, establish persistence, and scale attacks efficiently.
UAT-10147's operations are multifaceted, involving search engine optimization (SEO) fraud and data theft, with AI tools integrated at various stages of their attack cycle. They utilize AI to refine and troubleshoot exploits, automate post-exploitation workflows, and generate operational documentation. This approach not only facilitates exploitation and reconnaissance but also allows for large-scale offensive operations.
An analysis of the exposed directory revealed a target list comprising approximately 170,000 URLs. These were split into 17 smaller files for better parsing efficiency. The top targeted regions include the U.S., India, the U.K., Germany, and the Netherlands. Attack chains typically involve exploiting known vulnerabilities for remote code execution on websites or vulnerable IIS servers, followed by automated malware installation for SEO fraud or data theft. In some cases, web shells are deployed, leading to persistent access through backdoors like BadIIS.
For engineers and sysadmins, this development highlights the need for vigilance and proactive measures. Ensuring systems are up to date with patches, monitoring for unusual activities, and employing robust security frameworks can mitigate the risks posed by such sophisticated attacks.
The Linux Camp teaches these topics as hands-on labs on real virtual machines, verified as you type.