Back to News
Cybersecurity

UAT-10147: A New AI-Driven Cyber Threat Targeting Global Servers

A Chinese-speaking cybercrime group, UAT-10147, has been identified leveraging AI to enhance server attack capabilities, posing significant risks to various sectors.

Recent investigations have unveiled a Chinese-speaking cybercrime group known as UAT-10147, which is actively targeting Windows and Linux web servers across multiple sectors, including education, media, technology, and gaming. The group's operations have been predominantly focused on countries like Brazil, Bolivia, China, Canada, and Vietnam. Notably, UAT-10147 is utilizing advanced AI techniques to scale its attack strategies, incorporating the SPECTRE vulnerability alongside sophisticated EDR (Endpoint Detection and Response) bypass methods and Linux rootkits to compromise server security.

For businesses, the emergence of UAT-10147 underscores the critical need for enhanced cybersecurity measures, particularly for organizations operating web servers in the affected sectors. The ability of this group to deploy AI-driven attacks means that traditional security protocols may be insufficient to counter evolving threats. Companies must prioritize the implementation of robust security frameworks, including real-time monitoring and updating of software defenses, to mitigate the risks posed by such advanced cybercriminal networks. The significance of this development lies not only in its immediate implications for server security but also in highlighting the growing intersection of AI and cybersecurity, which could redefine the landscape of cyber threats and defenses in the near future.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html)*