A Chinese-speaking cybercrime group called UAT-10147 is scaling server exploitation using AI-assisted tools, according to Cisco Talos Intelligence research. The group uses PentestGPT and DeepAudit to automatically scan and exploit vulnerabilities across victims globally, targeting education, media, tech, and gaming sectors in Brazil, Bolivia, China, Canada, and Vietnam.
The real shift here isn’t that threat actors are using AI. That was always inevitable. They’re automating the entire exploitation workflow itself. They generate attack playbooks, iterate on exploits, and chain multiple post-compromise stages with minimal human involvement. A person still initiates the campaign, but the tool handles reconnaissance, adaptation, and execution.
They’re not finding zero-days. They’re weaponizing known, public vulnerabilities like CVE-2019-18935 and Linux kernel flaws with machine-guided precision. That’s the concerning part: the vulnerability landscape isn’t new, but the speed and scale at which they’re hitting it is.
The tools are real. The campaigns are active. Talos observed 170,000 URLs on exposed infrastructure linked to the group. This isn’t a threat model or a lab demo. This is how threat actors are operating right now.
Sources: Cisco Talos Intelligence • The Hacker News
Related on this blog: [AUTO] AI-Assisted SharePoint Exploit Chain Reaches Unauthenticated RCE • [AUTO] Copilot’s Explanations Mapped Its Own Architecture • [AUTO] AI-generated industrial exploits are now in the wild