A Chinese-speaking cybercrime group designated UAT-10147 is targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors, according to a report published by Cisco Talos. The threat activity surfaced after researchers discovered an open directory hosted at 139.180.197[.]150 communicating with a compromised machine. The vast majority of targeted servers are located in Brazil, Bolivia, China, Canada, and Vietnam, while target lists recovered from the infrastructure indicate that destinations in the United States, India, the United Kingdom, Germany, and the Netherlands form the top five intended endpoints.
Initial Access and Exploitation via Open-Source Frameworks
The actor leverages publicly disclosed vulnerabilities to gain initial access at scale, according to findings from Cisco Talos. To automate intrusion activities and secure persistence, UAT-10147 relies on a combination of open-source offensive tools that include DeepAudit, ysoserial, Metasploit, PentestGPT, alongside various privilege escalation exploits. Attack chains typically exploit known flaws to achieve remote code execution on a website or a vulnerable Internet Information Services (IIS) server before running automated scripts to install malware for search engine optimization (SEO) fraud and data theft. Select instances involve deploying a web shell that paves the way for BadIIS and additional backdoors.
Did you know? UAT-10147 splits its recovered target lists containing approximately 170,000 URLs into 17 smaller files of about 10,000 URLs each to parse the sets more efficiently.
AI-Powered Tools and Automation in the Attack Lifecycle
UAT-10147 integrates artificial intelligence-powered tools at various phases of the attack cycle to facilitate exploitation, reconnaissance, payload generation, validation, and persistence, according to Cisco Talos. The group accomplishes this by leveraging artificial intelligence to troubleshoot logic, refine exploits, validate exploits, automate post-exploitation workflows, and generate operational documentation. The group installs PentestGPT, an open-source autonomous pentesting framework, on command-and-control servers to scan web servers and execute relevant proof-of-concept exploits. Additionally, the actor uses an AI-driven framework called DeepAudit for vulnerability scanning, though Cisco Talos reported finding no evidence of the threat actor exploiting vulnerabilities discovered by DeepAudit in victim environments.
Windows Attack Chain and SPECTRE Deployment
On Windows targets, the group deploys batch scripts that use certutil to download a privilege escalation tool named EfsPotato alongside secondary scripts and Quasar RAT from the remote server adminapi.tippusoni[.]in, according to Cisco Talos. The threat actor uses EfsPotato to gain elevated system privileges, configure Microsoft Defender exclusions, and delete initial payloads to cover tracks. Follow-on implants include Gh0stCringe and a previously unreported cross-platform implant dubbed SPECTRE. Persistent access is established using a scheduled task named “Google Chrome Start.” The core BadIIS malware deployed in these attacks is the same variant operating under a malware-as-a-service model used by multiple Chinese-speaking cybercrime groups.
Linux Attack Vectors and Kernel Rootkit Integration
Linux attacks leverage various known vulnerabilities for initial footholds followed by local privilege escalation exploits, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847, according to Cisco Talos. Once root access is unlocked, the threat actor deploys backdoors such as Noodle RAT, SPECTRE, and Meterpreter. Weaponized vulnerabilities in the campaign include Zimbra flaw CVE-2022-27925, AjaxPro flaw CVE-2021-23758, Telerik UI flaw CVE-2019-18935, and Alibaba Nacos flaws CVE-2021-29441 and CVE-2021-29442. Data exfiltration is routed to a legitimate cloud-based configuration management service to blend traffic with normal administrative operations.
Cisco Talos notes that the newly discovered SPECTRE malware marks a major advancement in standard intrusion toolkits by combining cross-platform command-and-control functions, process injection, credential harvesting, anti-analysis measures, and capabilities to bypass kernel-level endpoint detection and response mechanisms. The Windows variant uses the bring-your-own-vulnerable-driver technique and targeted kernel writes to unlink registered endpoint detection and response callbacks from doubly-linked lists, rendering security products such as CrowdStrike Falcon, SentinelOne, and Microsoft Defender blind to new process and thread creations. The Linux variant deploys an integrated kernel-level rootkit dubbed Specter as a kernel module to ensure persistent, kernel-level control that survives reboots.
Pro Tip: Security teams should monitor for unauthorized modifications to endpoint detection and response driver callbacks and audit scheduled tasks for deceptive names such as “Google Chrome Start” to detect early-stage UAT-10147 compromise.
Frequently Asked Questions
What is UAT-10147?
UAT-10147 is a Chinese-speaking cybercrime group that targets Windows and Linux web servers globally to conduct search engine optimization fraud and data theft using AI-powered tools and open-source frameworks, according to Cisco Talos.
How does UAT-10147 evade detection on compromised hosts?
The threat actor uses the SPECTRE implant to perform targeted kernel writes that unlink endpoint detection and response callbacks, blinding security products like CrowdStrike Falcon, SentinelOne, and Microsoft Defender, according to Cisco Talos. They also route exfiltrated data through legitimate cloud-based configuration management services.

What is the SPECTRE implant?
SPECTRE is a cross-platform backdoor written in C that features obfuscation, anti-analysis protections, process injection, and kernel-level endpoint detection and response bypass functionality, according to Cisco Talos.
Which industries and regions are primarily affected?
Organizations in the education, media, technology, and gaming sectors are targeted, with the vast majority of compromised machines located in Brazil, Bolivia, China, Canada, and Vietnam, according to Cisco Talos.
Stay informed on the latest threat intelligence developments by subscribing to our security newsletter or exploring our archive of recent cybersecurity reports.