Skip to content

Build1 publisher3 min readPublished

Talos puts a name to the AI retry loop: UAT-10147 fixes its own failed exploits

The interesting part of the SPECTRE report is not the implant. It is an adversary using AI to diagnose failed exploit attempts and generate retry steps against a list of about 170,000 URLs.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Cisco Talos published a write-up titled "UAT-10147: A Chinese-speaking adversary integrates agentic AI into post-compromise operations", dated 2026-08-20, rated High severity.
  • After breaching public-facing servers, the threat actor uses AI to speed up the fixing and testing of attack code, then deploys SPECTRE, rootkits and existing RATs to Windows and Linux systems.
  • The attacker manages a target list of about 170,000 URLs and uses AI tools to fix exploit code, analyse the causes of failures, and generate retry steps.
  • The actor automates the search for writable paths, ViewState RCE and web shell deployment using Python scripts that include ysoserial, and checks quality with AI.
  • DeepAudit was installed on the management server, but there is no direct evidence that the vulnerabilities found by the tool were used in actual attacks.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Cisco Talos has published a write-up on UAT-10147, a Chinese-speaking actor it says has folded agentic AI into post-compromise operations, rated High severity and dated 20 August 2026 [1]. The part that changes defensive math is not the tooling but the workflow: Talos reports that after breaching a public-facing server, the actor uses AI to speed up the fixing and testing of attack code, then deploys the SPECTRE implant, rootkits and existing RATs to Windows and Linux hosts [2].

Read the loop carefully. According to Talos, the actor manages a target list of roughly 170,000 URLs and uses AI tools to fix exploit code, analyse the causes of failures, and generate retry steps [3]. Alongside that, the search for writable paths, ViewState RCE and web shell deployment is automated with Python scripts that bundle ysoserial, with AI used to check output quality [4]. That is the exploit-fix-retest cycle described as a production process rather than an experiment, and it matters because a failed attempt has historically bought defenders time: hours or days while a human operator worked out what broke.

The honest limit is that Talos does not quantify the compression. "Faster repeated attacks supported by AI" appears as one of four stated reasons for the High severity rating, next to the 170,000-URL list, targeting that spans government, education and technology organisations, and cross-platform post-compromise tooling for Windows and Linux [6]. No figure for time-to-retry, attempt volume per host or success rate appears in the material [20]. Treat this as the first concrete operational description of the pattern, not a measurement of it.

Everything downstream is unremarkable, which is the point. Initial access is exploitation of a known vulnerability on an internet-facing web server for remote code execution or a web shell [7]. On Windows, batch files and certutil pull down EfsPotato, QuasarRAT, BadIIS and other tools [8]; where SeImpersonatePrivilege is available, EfsPotato is used to escalate and the IIS directory is added to the Defender exclusion list [9]; appcmd enumerates IIS sites before the actor sets up unauthorised administrator and RDP accounts, persistence tasks and BadIIS or SPECTRE [10]. SPECTRE registers, then takes commands over HTTP and returns results to its C2 [11]. On Linux, a web shell follows code execution, several known privilege escalation methods are attempted, and SPECTRE lands with the Specter rootkit, which uses ftrace hooks to hide processes, files and network traffic [12]. SPECTRE itself is described as a cross-platform implant with Linux rootkit and bring-your-own-vulnerable-driver capability [19], and the related family list runs to Noodle RAT, Gh0stCringe and Meterpreter [13]. The AI sits on the operator's side of the wire, supporting code creation, testing and troubleshooting; nothing in the described implant behaviour requires it [22].

Two caveats worth holding. DeepAudit was found installed on the management server, but Talos says there is no direct evidence that vulnerabilities it found were used in actual attacks [5]. And no CVE is named [14], so there is no single patch to prioritise: the stated mitigations are fast patching of public servers or blocking initial exploitation at a WAF or IPS, restricting outbound traffic from web processes and certutil, stripping SeImpersonatePrivilege and management rights from web services, and refusing unsigned or suspicious kernel modules [16].

What to watch on your own telemetry: outbound HTTP POSTs from web servers, certutil downloads, IIS configuration enumeration, Defender exclusion changes, unexpected high-privilege logon tasks and RDP accounts on Windows, and suspicious kernel modules on Linux [15]. Upstream, Talos notes the attacker infrastructure contacts large numbers of URLs and vulnerability-verification destinations in a short window [17]. If the retry loop is genuinely tightening, that burst signature is where it will show up first, and repeat probes against a host that already rejected one attempt stop being noise.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories