Security1 distinct publisher3 min readUpdated
Cisco Talos says UAT-10147, a Chinese-speaking group doing SEO fraud and data theft, wired AI tooling into exploitation, validation and persistence. An open directory gave the operation away.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Cisco Talos says UAT-10147, a Chinese-speaking group doing SEO fraud and data theft, wired AI tooling into exploitation, validation and persistence. An open directory gave the operation away.
Cisco Talos has published details on UAT-10147, a Chinese-speaking, financially motivated crew hitting internet-facing Windows and Linux web servers worldwide and folding AI tooling into the work once it has code execution [1][2]. The point is not the malware, which is ordinary; it is that Talos assesses AI-generated exploitation guidance, automation and validation workflows let this group run post-compromise operations that would traditionally require expertise its operators do not have [3][4].
Talos discovered the group in early 2026 and describes its business plainly: SEO fraud and data theft [5]. Victims sit in government, universities, media, technology and gaming [1], with compromised servers observed in Brazil, Bolivia, China, Canada and Vietnam [6]. Initial access is unremarkable, which is the part defenders control: publicly disclosed vulnerabilities, exploited at scale [2].
The group's own infrastructure is the more instructive find. Talos noticed a compromised machine talking to a download server at 139.180.197[.]150 and found an open directory on it [7]. Inside was a text file holding roughly 170,000 target URLs, which the actor had split into 17 files of about 10,000 each because scanning the whole list at once was inefficient, using the letter "w" as shorthand for the Chinese character meaning 10,000 [8][9]. Seventeen files of ten thousand is the entire list, so this is a queue management decision, not a sample [10].
The toolkit is off the shelf: Metasploit, ysoserial, PentestGPT, DeepAudit and several privilege escalation exploits [11]. On Windows, after remote code execution or an implant, a batch script commonly named "back.txt" or "back.bat" uses certutil to pull down the EfsPotato privilege escalation tool renamed as "prcc1.rar", a secondary script "bai.bat", and a QuasarRAT payload [12]. Where the actor prefers hands on keyboard, a web shell goes in first and BadIIS is set up manually, with persistence through an additional backdoor [13].
Talos assesses with moderate-to-high confidence that UAT-10147 belongs to an emerging class of financially motivated intrusion operators using agentic AI to operationalise offensive tradecraft at scale [14]. The behaviours it cites are specific rather than atmospheric: iterative exploit refinement, adaptive troubleshooting, post-exploitation automation, exploit validation workflows and generation of operational documentation [15]. Talos calls that a transition from AI-assisted scripting toward semi-autonomous offensive orchestration [16], and reports observing AI-generated operational playbooks, exploit automation scripts and troubleshooting logic supporting real intrusions [3].
Read against the operational picture, the consequence is a tempo problem. The skill gap between a crew that mass-scans 170,000 URLs [8] and a crew that can pivot, escalate and persist reliably is what has historically kept most opportunistic compromises shallow. Talos's assessment is that the gap is narrowing because the hard parts are being written, debugged and documented by tooling rather than by the operator [4]. If that holds, the value of an unpatched internet-facing web server to a low-skill group goes up, and the window between disclosure and exploitation stops being a buffer.
Watch for whether Talos or other vendors publish the AI-generated playbook artifacts themselves, since documentation and troubleshooting logs are the clearest evidence of how much of this workflow is actually autonomous [3][16]. Watch the BadIIS side, which is the revenue mechanism and the most likely place a victim notices anything [13]. And watch the country distribution in that 170,000-URL list against your own exposed estate, because the intake queue is the operation's roadmap and it is already public in outline [8][9].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Talos says the actor demonstrated iterative exploit refinement, adaptive troubleshooting, post-exploitation automation, exploit validation workflows and operational documentation generation.
Talos states this indicates a transition from AI-assisted scripting toward semi-autonomous offensive orchestration, unlike traditional use of generative AI for simple scripting assistance.
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology and gaming sectors.
The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale.
Talos observed AI-generated operational playbooks, exploit automation scripts and troubleshooting logic supporting real-world intrusions, and says UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation and persistence workflows.
Talos assesses that integrating AI-generated exploitation guidance, automation and validation workflows enables threat actors to scale complex attacks more efficiently while reducing the expertise traditionally required for advanced post-compromise operations.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party vendor telemetry, no independent corroboration
The report supplies specific, checkable artefacts: a C2 IP with an open directory, script filenames, certutil download chain, renamed tools (EfsPotato as prcc1.rar), QuasarRAT as svchosts.exe, verbatim Add-MpPreference commands, scheduled-task name, victim geography and sectors, and a recovered target list. That is strong for a single report. It is capped by the cluster containing only one publisher — the vendor itself — with no second-vendor, CERT or victim confirmation, no CVEs for the claimed public-vulnerability access, and no attribution of the AI artefacts to identified models or services.
Live multi-country campaign; intended scale far exceeds confirmed victims
This is in-the-wild activity, not a lab demonstration: compromised servers in five named countries across five sectors, multiple deployed implants (BadIIS, QuasarRAT, Gh0stCringe, SPECTRE) and a queued target list of roughly 170,000 URLs. Adoption is held below the midpoint band's upper end because the report gives no count of successful compromises, no timeline of infections, and no measure of how much of the 170,000-URL list was ever exploited — the large number is intent, not confirmed footprint.
Agentic framing runs ahead of the published artefacts
The intrusion mechanics and indicators are well evidenced, but the headline framing — 'agentic AI' and a transition to 'semi-autonomous offensive orchestration' — is inferred from generated documentation, refinement patterns and the presence of PentestGPT/DeepAudit rather than from demonstrated model-driven runtime decision-making; the automation actually shown is deterministic batch scripting. Talos itself hedges at moderate-to-high confidence, which limits the overstatement, so the gap is modest and positive rather than severe.
Security vendor publishing threat research that reinforces its own product narrative
The sole source is Cisco Talos, the research arm of a security vendor; publishing novel-actor research and an AI-threat capability thesis supports brand authority and demand for the exposure-management and endpoint products its parent sells. That incentive is partly offset by the report's specificity — indicators, filenames and commands that competitors and defenders can test — and by the explicit confidence hedge. No independent publisher is present to dilute the vendor's framing.
Solid on mechanics, weaker on the AI-autonomy conclusion
Confidence is moderate: the intrusion chain, indicators and victimology are described with operational precision by a credible first-party investigator, so the defender-actionable core is likely accurate. The interpretive layer — agentic, semi-autonomous AI orchestration — depends on inference from artefacts, is self-hedged at moderate-to-high confidence, and is uncorroborated by any second source in this cluster, which caps overall confidence near the middle of the range.
security
An SEO fraud crew is now shipping kernel rootkits and BYOVD, and that is the story1 distinct publisher
security
Talos tells the story instead of the matrix, and BEC's new economics fall out1 distinct publisher
security
North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.