A Chinese-speaking criminal group identified as UAT-10147 has escalated its tactics by combining AI-assisted tools with known remote-code-execution vulnerabilities to infiltrate web servers across government, education, media, gaming, and technology sectors. With operations spanning multiple countries, the attackers amassed a list of about 170,000 URLs to target. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
AI Agents as Operational Assistants
Researchers at Cisco Talos observed that UAT-10147 isn’t just using AI tools to write code—they’ve embedded agent-like AI throughout their attack workflows. These include creating exploit playbooks, troubleshooting logic, validation routines, and detailed post-intrusion procedures. Rather than a single script, the setup resembles an AI assistant that guides a human operator through finding vulnerabilities, testing payloads, adjusting failures, and maintaining access. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
Attackers exploited well-known flaws in platforms including Zimbra, AjaxPro, Nacos, and Telerik, on both Windows and Linux systems. On Windows, modules like BadIIS were used to manipulate search results and install persistent backdoors. On Linux, after deploying a web shell, attackers used local privilege escalation—Dirty Pipe among them—to gain root access and install implants. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
Automation Increases Speed and Stealth
Evidence shows the AI tools are involved at every phase: discovery, exploitation, validation, installation of web shells, data exfiltration, and persistence. These workflows automate failure recovery—if a given exploit or path doesn’t succeed, the system can reroute to alternate steps. Attackers also used cloud configuration services to blend stolen data with typical web traffic, making detection more difficult. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
Key indicators of compromise (IoCs) have emerged: suspicious IPs and domains, various malicious files (scripts and payloads), routine components like web shells, and diagnostic or post-exploitation tools automatically generated via AI. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
Defensive strategies must evolve. Experts recommend treating internet-facing web servers as critical assets, applying patches without delay, limiting exposure of administrative endpoints, securing secret material (like ASP.NET MachineKey), and monitoring for anomalies—unexpected accounts, outbound connections, or IIS configuration changes. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
While UAT-10147 still depends on operator engagement, the group’s approach accelerates every step, turning known vulnerabilities into far more accessible avenues for attack. Shrinking the window between exploit discovery and deployment becomes easier with automation. ([cybersecuritynews.com](https://cybersecuritynews.com/chinese-hackers-use-ai-agents/))
The rise of AI-driven agents in cybercrime reflects a broader shift in how attacks are conducted. Defenders must focus not only on traditional patching and configuration but also on visibility into workflows and tooling that reduce human error—because the attackers already are. Strong detection, proactive threat intelligence, and hardening known weak points are more vital than ever.