UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
AI Summary
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
AI-extracted · verify before operational use
Extracted Entities 10 found
Indicators of Compromise 14 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 139[.]180[.]197[.]150 | Details → |
| Domain | adminapi[.]tippusoni[.]in | Details → |
| Filename | back.txt | Details → |
| Filename | back.bat | Details → |
| Filename | bai.bat | Details → |
| Filename | user.bat | Details → |
| Filename | prcc1.rar | Details → |
| Filename | svchosts.exe | Details → |
| Filename | dll.zip | Details → |
| Filename | up.ashx | Details → |
| Filename | sss.ashx | Details → |
| Filename | check_paths.py | Details → |
| Filename | deploy_implant.py | Details → |
| Filename | deploy_shell.py | Details → |