CISCO Talos recently reported on UAT-10147, a Chinese-speaking cybercrime group leveraging agentic AI for web server exploitation and data theft. The group targets over 170,000 URLs across government, education, and tech sectors globally, utilizing automated tools alongside traditional exploit frameworks. Their attack strategies vary for Windows and Linux systems, employing techniques like web shell exploitation and privilege escalation.
They focus on financial gain through SEO fraud and intellectual property theft, with significant operational security failures revealing their internal documentation. Organizations are advised to enhance security measures, patch vulnerabilities, and monitor for suspicious activities to mitigate these threats.