Skip to main content
HIGH Threat Intel #Agentic AI#Data Theft

UAT-10147: Agentic AI Enhances Post-Compromise Operations

4 min read Runtime Rebel Intel
Primary source: blog.talosintelligence.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: UAT-10147 targets global web servers, using AI for scaled exploitation and data theft across multiple sectors.
  • Affected systems: Vulnerable Windows and Linux web servers in government, education, media, technology, and gaming organizations.
  • Remediation: Prioritize patching known web server vulnerabilities and enhance detection for post-compromise activities.

Advertisement

Overview

Cisco Talos has identified a Chinese-speaking cybercrime group, tracked as UAT-10147, integrating advanced agentic AI systems into its post-compromise operations. This actor targets vulnerable Windows and Linux web servers globally, impacting a diverse range of organizations including government, education, media, technology, and gaming sectors. Unlike traditional generative AI usage for simple scripting, UAT-10147 leverages AI for iterative exploit refinement, adaptive troubleshooting, post-exploitation automation, and operational documentation generation, enabling them to scale complex attacks more efficiently.

UAT-10147’s Agentic AI Post-Compromise Operations

The distinguishing characteristic of UAT-10147 is its sophisticated use of AI-driven tooling across multiple stages of an intrusion. According to Cisco Talos, the threat actor employs AI for:

  • Exploitation: Generating and refining exploit guidance.
  • Reconnaissance: Automating information gathering.
  • Payload Generation & Validation: Creating and testing malicious payloads.
  • Persistence Workflows: Establishing enduring access.
  • Adaptive Troubleshooting: Adjusting tactics in real-time.
  • Operational Documentation: Producing playbooks and guides.

This capability significantly lowers the barrier to entry for advanced operations, allowing the group to conduct large-scale campaigns with reduced reliance on highly specialized human expertise. The adversary utilizes a mix of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, and DeepAudit, alongside various privilege escalation exploits to automate their intrusion operations and maintain persistence.

Targeting and Post-Compromise Tactics

UAT-10147 gains initial access by exploiting publicly disclosed vulnerabilities in internet-exposed web servers. Upon successful remote code execution (RCE) or initial server compromise, the actor often deploys automated scripts to install malware for search engine optimization (SEO) fraud or data theft. In other scenarios, a web shell is established, allowing for manual deployment of the BadIIS malware and additional backdoors.

The Windows infection chain typically involves multi-stage batch scripts, such as back.txt or back.bat. These scripts use certutil to download a privilege escalation tool like EfsPotato (renamed prcc1.rar), a secondary batch script (bai.bat), and the QuasarRAT payload (disguised as svchosts.exe). After gaining elevated privileges, the scripts modify the Windows Registry and use PowerShell to add directories to Windows Defender exclusion lists, evading detection. Persistence is achieved by creating deceptive scheduled tasks, such as “Google Chrome Start,” configured to run the malware with high privileges upon user login. Talos also observed the deployment of other implants in similar campaigns, including Gh0stCringe and SPECTRE. To efficiently manage their targets, UAT-10147 maintains lists of approximately 170,000 URLs, segmented into smaller files for performance optimization. Understanding how to detect BadIIS malware UAT-10147 deploys requires vigilance against these specific TTPs.

Actionable Recommendations and Mitigations

Organizations must prioritize patching known vulnerabilities in web servers, particularly those that are internet-facing. Given UAT-10147’s use of AI to scale exploitation, proactive vulnerability management is more critical than ever.

  • Patch Management: Immediately apply security patches for all web server software, operating systems (Windows, Linux), and associated components. Focus on known vulnerabilities often exploited for initial access.
  • Endpoint Detection and Response (EDR): Enhance EDR capabilities to detect anomalous process execution, privilege escalation attempts (e.g., EfsPotato), and modifications to Windows Defender exclusions.
  • Network Monitoring: Monitor network traffic for unusual outbound connections from web servers, which could indicate C2 communication or data exfiltration.
  • Web Server Hardening: Implement web application firewalls (WAFs) and regularly review web server configurations to minimize attack surface.
  • Identity and Access Management: Enforce strong authentication, least privilege principles, and multi-factor authentication (MFA) for administrative interfaces and critical systems.
  • Incident Response Planning: Develop and rehearse incident response plans specific to web server compromises and data breaches.
  • Behavioral Analysis: Implement security solutions capable of behavioral analysis to identify AI-driven anomalous activity, even if specific signatures are not yet available. This will help mitigate UAT-10147 web server compromise.

Related: Agentic AI: New Security Challenges for Confidential Computing, Agentic AI Cyber Warfare: Risks of Autonomous Offensive Operations

Advertisement

Advertisement