Return to Threats

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

thehackernews.com 2026-08-24 malicious AI use Critical

What Happened

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

Why It Matters

Reported facts: Researchers describe a Chinese-speaking cybercrime group, UAT-10147, using AI to scale attacks against Windows and Linux web servers across multiple sectors and countries, including deployment of SPECTRE with EDR bypass and a Linux rootkit. The activity targets education, media, technology, and gaming organizations in regions such as Brazil, Bolivia, China, Canada, and Vietnam. RealGround analysis: This is a clear case of malicious AI use where adversaries leverage AI to automate and scale server exploitation, increasing both speed and volume of attacks against internet-facing infrastructure. Organizations should harden AI-assisted security operations and conduct continuous red teaming to simulate AI-augmented attackers, ensuring their detection, response, and server hardening strategies keep pace with automated, AI-driven intrusion techniques.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html

Talk to AI CISO