Security1 distinct publisher3 min readUpdated
Cisco Talos says a Chinese-speaking crew paired PentestGPT and DeepAudit with Metasploit and a 170,000-URL target list to compromise web servers at scale. Every entry flaw named is years old.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
The interesting part of the Talos account is not the implant, it is the throughput. The AI tooling is doing clerical labour: refining exploits, troubleshooting logic, validating that an exploit actually landed, automating post-exploitation, and generating operational documentation [7]. None of that is a new capability. All of it is the part of mass exploitation that historically needed a human, which is why campaigns against internet-facing servers usually run out of operator attention long before they run out of vulnerable hosts.
The infrastructure choice fits that reading. Talos researcher Joey Chen says exfiltrated data was routed to a legitimate cloud-based configuration management service so the traffic blends with normal administrative operations [20], and describes the setup as an asynchronous exfiltration sink the operators poll to confirm exploitation across victims without maintaining reverse shells or inbound connections [21]. Pair that with a 170,000-URL list chopped into 17 files of roughly 10,000 [8], which is arithmetically exact [23], and the shape is a job queue with workers, not a person with a terminal.
Then there is the geography, which does not line up. The heaviest observed victim concentration is Brazil, Bolivia, China, Canada and Vietnam [2]. The top five destinations on the actor's own target list are the United States, India, the United Kingdom, Germany and the Netherlands [9]. Zero countries appear in both sets [24]. Anyone in the second group reading the first group as a threat profile is reading the wrong column.
On the entry side, nothing here needed research. The named weaponised flaws are in Zimbra, AjaxPro, Telerik UI for ASP.NET AJAX and Alibaba Nacos [19], with assignment years between 2019 and 2022 [26]. The Linux privilege escalation set reaches back further, from CVE-2022-0995 to CVE-2010-3904, a twelve-year span with nothing newer than 2022 [17][25]. Talos's own summary is blunt about it: publicly disclosed vulnerabilities, used to gain initial access at scale [4]. Patch latency on exposed servers is the variable the attacker is exploiting, and it is now being consumed by an automated pipeline rather than a queue of humans.
Two cautions on the detection side. On Windows, EfsPotato is used to elevate and then configure Microsoft Defender exclusions [12], and the initial payloads are deleted afterwards [13], so quiet endpoint telemetry from one of these hosts is not evidence of anything. And the BadIIS component is the same variant sold under a malware-as-a-service model and used by multiple Chinese-speaking crews [16], which means a BadIIS hit tells you which shop supplied the module, not which crew is in your server.
Finally, the thin part. The report's own framing puts an EDR bypass in SPECTRE and a Linux rootkit in the chain [22], but what is actually described in the available summary is the Defender exclusion route [12] and a spread of post-root implants including Noodle RAT, SPECTRE and Meterpreter calling out to C2 [18]. The bypass mechanism and the rootkit sit in parts of the two-part report not reproduced here [1].
Ranked by verification strength, evidence, and original report placement.
Cisco Talos published a two-part report describing a Chinese-speaking cybercrime group dubbed UAT-10147 that targets Windows and Linux web servers globally across the education, media, technology and gaming sectors.
The actor used a mixture of open-source offensive frameworks including Metasploit, ysoserial, PentestGPT, DeepAudit and multiple privilege escalation exploits to automate intrusion operations and establish persistence.
UAT-10147 conducts SEO fraud and data theft while integrating AI-powered tools at various phases of the attack cycle, including exploitation, reconnaissance, payload generation, validation and persistence.
The AI use described involves refining exploits, troubleshooting logic, automating post-exploitation workflows, validating exploits and generating operational documentation.
Follow-on implants include Gh0stCringe and a previously unreported cross-platform implant dubbed SPECTRE.
The published report is framed as UAT-10147 deploying SPECTRE with an EDR bypass and a Linux rootkit.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor forensics, no outside corroboration
The technical substance is unusually specific for a cluster this small: named staging host, named privilege escalation tool, a disguised scheduled task, a shared BadIIS variant, eleven CVEs across Windows and Linux paths, and a direct researcher quote explaining the Nacos exfiltration design. All of it, however, traces to one Cisco Talos report relayed by a single publisher (the second cluster item is the same article with a tracking parameter), so nothing is independently verified and no IOC hashes or victim counts are provided.
Confirmed in the wild, scale asserted not counted
Real-world use is established: compromised machines were observed, victim geography is characterised, follow-on implants were deployed, and PentestGPT sat on the live C2 running proof-of-concept exploits with at least one successful website exploitation. What is missing is magnitude - the 170,000-URL file is a target list, not a victim list, and the report gives no confirmed compromise count, dwell time or impact figures. The AI component is also only partly operationalised, since DeepAudit findings were not seen exploited against victims.
AI framing leads; old CVEs do the work
The headline frames an AI-scaled attack operation, and AI tooling is genuinely present, but the supplied evidence positions it as exploit refinement, troubleshooting, workflow automation, validation and documentation generation - assistance, not autonomy. Initial access rests entirely on publicly disclosed flaws from 2019 to 2022, Linux escalation on CVEs as old as 2010, and the malware stack on commodity, malware-as-a-service and long-known families such as BadIIS, Quasar RAT and Gh0st RAT derivatives. Talos itself reports no evidence that DeepAudit-discovered vulnerabilities were exploited at victims, which cuts against the most novel-sounding element. The gap is modest rather than severe because the publisher does not embellish beyond its source.
Vendor research amplified by one aggregating outlet
The sole primary source is threat research from Cisco Talos, a commercial security vendor whose products benefit when the sophistication of AI-assisted attacks is salient; the disclosure is nonetheless technically detailed and self-limiting in places, notably the admission that no DeepAudit-found vulnerability was seen exploited. On the publishing side, the cluster is one outlet whose model rewards AI-and-threat-actor framing, and the same article appears twice with a tracking parameter, which inflates apparent coverage. No disclosure of the vendor relationship appears in either item.
Coherent and specific, but single-sourced
Internal consistency is high and the derived arithmetic checks out (17 files of ~10,000 covers 170,000; the CVE year prefixes bound the age claims), so the descriptive core is reliable. Confidence is held mid-range because everything depends on one vendor report relayed by one publisher, the cluster's two items are the same article, and the operational magnitude of the campaign is unquantified.
build
Talos puts a name to the AI retry loop: UAT-10147 fixes its own failed exploits1 distinct publisher
security
Talos finds a commodity crew running agentic AI, and a target list of 170,000 URLs1 distinct publisher
security
An SEO fraud crew is now shipping kernel rootkits and BYOVD, and that is the story1 distinct publisher
build
PyInstaller exits zero, then the real work starts: notarization traps that report success1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 24, 2026