Cybersecurity experts have uncovered details about a Chinese-speaking cybercriminal group known as UAT-10147. This group is targeting Windows and Linux web servers worldwide, focusing on sectors such as education, media, technology, and gaming.
Geographical Targets and Tactics
UAT-10147 targets servers primarily in Brazil, Bolivia, China, Canada, and Vietnam. The group’s activities were traced back to a directory at “139.180.197[.]150,” which connected with compromised devices. According to Cisco Talos, they exploit known vulnerabilities for initial access, using tools like Metasploit and PentestGPT to automate their operations.
By leveraging artificial intelligence, UAT-10147 refines exploits and automates various phases of their attacks, from reconnaissance to persistence. This method allows them to implement offensive strategies on a large scale, making them a significant threat.
Exploiting Vulnerabilities with AI
An analysis revealed a list of approximately 170,000 URLs targeted by the attackers, divided into smaller subsets for efficiency. The most targeted regions include the U.S., India, the U.K., Germany, and the Netherlands. Their attack strategy involves exploiting security flaws to execute remote code and deploy malware for SEO fraud or data theft.
The group’s use of AI tools like DeepAudit for vulnerability scanning highlights their sophisticated approach. Although there is no evidence yet of vulnerabilities being exploited by this tool in victim environments, it suggests potential for future attacks or even defensive improvements.
Advanced Malware Deployments
Among the tools used by UAT-10147 is the SPECTRE implant, a cross-platform backdoor with advanced features like process injection and credential theft. This malware enables remote command-and-control operations while bypassing endpoint detection and response systems.
The Linux version of SPECTRE employs a kernel-level rootkit called Specter, developed using AI and human expertise. This rootkit maintains control over compromised hosts, surviving reboots and evading security measures, which poses a significant challenge for cybersecurity defenses.
The use of AI-driven techniques by UAT-10147 marks a new era in cyber warfare, blending technology with malware-as-a-service models. As these methods evolve, they underline the need for robust cybersecurity strategies to counteract such sophisticated threats.
