{"id":243137,"date":"2026-08-25T01:22:19","date_gmt":"2026-08-25T06:22:19","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/uat10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-linux-rootkit"},"modified":"2026-08-25T01:22:19","modified_gmt":"2026-08-25T06:22:19","slug":"uat10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-linux-rootkit","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/uat10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-linux-rootkit","title":{"rendered":"UAT10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/uat10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-linux-rootkit.jpg\"><\/a><\/p>\n<p>Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed <strong>UAT-10147<\/strong> that\u2019s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.<\/p>\n<p>The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at \u201c139.180.197[.]150,\u201d which was observed communicating with one of the compromised machines.<\/p>\n<p>\u201cThe actor leveraged publicly disclosed vulnerabilities to gain initial access at scale,\u201d Cisco Talos <a href=\"https:\/\/blog.talosintelligence.com\/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations\/\" target=\"_blank\">said<\/a> in a two-part report published last week. The actor employed a mixture of open-source offensive frameworks, including <a href=\"https:\/\/docs.metasploit.com\/\" target=\"_blank\">Metasploit<\/a>, <a href=\"https:\/\/github.com\/pwntester\/ysoserial.net\" target=\"_blank\">ysoserial<\/a>, <a href=\"https:\/\/pentestgpt.com\/\" target=\"_blank\">PentestGPT<\/a>, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that\u2019s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,32,6],"tags":[],"class_list":["post-243137","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-education","category-robotics-ai"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=243137"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/243137\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=243137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=243137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=243137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}