A Chinese-speaking group tracked as UAT-10147 is now using AI to automate the compromise of Windows and Linux web servers worldwide, according to reporting published 24 August 2026. For UK infrastructure teams, the detail that matters isn't the geography — it's the automation.
What's been disclosed about UAT-10147
The Hacker News reported on 24 August 2026 that UAT-10147, a Chinese-speaking threat actor, is targeting internet-facing Windows and Linux web servers globally, with the heaviest concentration of observed victims in Brazil, Bolivia, China, Canada and Vietnam. The group has been linked to SEO fraud and data theft as its primary monetisation routes rather than headline ransomware payouts.
Attack chains reportedly begin with exploitation of publicly known vulnerabilities to gain remote code execution on a website or a vulnerable IIS server. From there, an automated script installs and deploys malware tied to the group's SEO fraud or data-theft operations. No specific CVE identifiers or CVSS scores were disclosed in the reporting, so buyers should treat this as a tactics-and-tooling alert rather than a single patch advisory.
The tooling: Metasploit, ysoserial, PentestGPT and DeepAudit
What distinguishes this campaign is the tool mix. Alongside familiar open-source frameworks — Metasploit for exploitation and ysoserial for deserialisation attacks — UAT-10147 is reported to use PentestGPT and an AI-driven scanning framework called DeepAudit, combined with privilege-escalation exploits to automate both intrusion and persistence.
The AI layer is doing the grunt work that previously slowed down human operators: refining exploits, troubleshooting broken exploit logic, validating whether an attack chain actually works, automating post-exploitation steps, and even generating operational documentation. This is the shift buyers should register — it compresses the time between vulnerability disclosure and working exploitation at scale, which is exactly the pressure point that vulnerability management programmes are built to relieve.
Why EDR bypass and Linux persistence need a fresh audit
Because the campaign spans both Windows and Linux estates, single-platform defence assumptions no longer hold. Windows-heavy security teams that have under-invested in Linux telemetry — logging on web servers, application servers and container hosts — are the softer target here, precisely because attackers can automate reconnaissance and exploitation across mixed estates faster than defenders can review alerts manually.
UK buyers should treat this as a prompt to re-test whether their current tooling actually catches privilege-escalation and persistence attempts on Linux hosts, not just Windows endpoints. That means comparing how your endpoint security stack performs against rootkit-style persistence and EDR evasion on both operating systems, and revisiting the fundamentals in our EDR vs antivirus explainer if procurement decisions were made on Windows-centric assumptions.
- •Confirm Linux web/application servers have EDR agents, not just log forwarding
- •Check privilege-escalation detections cover both IIS and common Linux web stacks
- •Verify alerting doesn't silently deprioritise non-Windows hosts
- •Test whether internet-facing servers are visible in your attack surface inventory

Part of a wider pattern of AI-run intrusions
UAT-10147 isn't an isolated case. BleepingComputer reported on 31 July 2026 that a separate Chinese-speaking actor used DeepSeek AI and a tool called Hermes Agent to autonomously attack vulnerable servers with limited human involvement — a campaign only discovered because the attacker's own environment leaked API keys, exploit scripts, target lists, shell history and AI attack logs. Notably, those particular attacks did not succeed in compromising the intended servers.
Separately, The Hacker News reported in July 2026 that an AI agent compromised production infrastructure at Hugging Face, with unauthorised access detected to internal datasets and service credentials. Taken together with UAT-10147, the pattern is clear: AI is now a standard component of offensive tooling, not an experimental add-on, and it's being pointed at both external targets and, in the Hugging Face case, AI infrastructure itself.
What UK infrastructure teams should do now
None of the source reporting names specific CVEs, so the practical response is procedural rather than a single patch. Start by confirming patching cadence on internet-facing IIS and Linux web servers is measured in days, not weeks — automated exploitation removes the grace period that manual attacker workflows used to give defenders. This is a good moment to stress-test your attack surface management coverage against forgotten or shadow-IT web servers, since UAT-10147's targeting appears opportunistic across geographies rather than narrowly sector-specific.
Buyers should also ask vendors directly how their platforms detect AI-assisted attack chains — automated post-exploitation scripting, rapid exploit validation, and documentation-generation patterns leave behavioural fingerprints even when the underlying vulnerability is unknown. Read our broader look at AI-powered attacks and defence and the current best EDR platforms comparison before renewing or extending detection contracts this financial year.
