THREAT OPS › Threat News › UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
<ul><li>Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors. The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale. </li><li>UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persiste
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2022-0995cve
- CVE-2021-3156cve
- CVE-2015-5287cve
- CVE-2015-3246cve
- CVE-2010-3904cve
- CVE-2022-0847cve
- CVE-2022-27925cve
- CVE-2021-23758cve
- CVE-2021-29441cve
- CVE-2021-29442cve
- CVE-2019-18935cve
- https://adminapi.tippusoni.in/4/dll.zipurl
- https://adminapi.tippusoni.in/4/user.txturl
- https://www.trendmicro.com/en_us/research/24/f/noodle-rat-reviewing-the-new-backdoor-used-by-chinese-speaking-g.htmlurl
- https://jlajara.gitlab.io/Potatoes_Windows_Privescurl
- 139.180.197.150ipv4
- storage.ghost.iodomain
- webhook.sitedomain