
UAT-10147 Automates 170k Targets with AI Tools and SPECTRE Linux Rootkit via Exposed Directory
UAT-10147 used AI tooling to scale exploitation of public CVEs against 170k web servers, deploying SPECTRE and BadIIS after initial access. Evidence from an exposed directory and malware samples shows automated workflows distinct from broader attribution claims. The campaign highlights MaaS reuse and AI-driven persistence on Windows and Linux hosts.
UAT-10147 leveraged Metasploit, ysoserial, PentestGPT, and DeepAudit to refine exploits and automate post-exploitation after initial RCE via CVEs including CVE-2022-27925, CVE-2019-18935, and CVE-2021-3156. Batch scripts deployed EfsPotato for privilege escalation, excluded Microsoft Defender, then installed BadIIS, Quasar RAT under a scheduled task named Google Chrome Start, and the cross-platform SPECTRE implant with EDR bypass. The exposed directory contained the full target list with top destinations the US, India, UK, Germany, and Netherlands.
Technical evidence from the directory and malware samples shows operational scaling through AI for payload generation and validation, distinct from official attribution claims of a single Chinese-speaking group. BadIIS operates under a known MaaS model shared across multiple actors, while Linux chains used Noodle RAT and Meterpreter after LPE via CVE-2022-0847 and CVE-2022-0995. This pattern matches prior campaigns where open directories exposed target lists and C2 infrastructure.
The integration of AI into reconnaissance and persistence workflows allows smaller crews to sustain volume attacks across 170k endpoints. Procurement records and incident reports indicate similar automation in other clusters targeting Brazil, Bolivia, Canada, and Vietnam. Next phase likely involves expanded use of SPECTRE variants against additional IIS and Apache servers once current C2 domains are burned.
Independent verification of the open directory contents and malware hashes confirms the scale beyond single-victim reporting. Expect follow-on implants to shift C2 to cloud services to blend with legitimate traffic.
Talos: SPECTRE C2 infrastructure will migrate to at least three new cloud-hosted domains within 60 days of domain takedowns.
Sources (2)
- [1]Primary Source(https://blog.talosintelligence.com/uat-10147-ai-scaling/)
- [2]Supporting Source(https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html)