Cybersecurity researchers have identified UAT-10147, a Chinese-speaking threat group targeting Windows and Linux servers across education, media, and technology sectors. The group distinguishes itself by integrating agentic AI and AI-powered tools like PentestGPT and DeepAudit into their operations to automate vulnerability scanning, payload refinement, and post-compromise workflows. By leveraging these technologies alongside traditional offensive frameworks, they conduct large-scale SEO fraud and data theft operations.
The group's sophisticated toolkit includes a new cross-platform implant named SPECTRE, which features kernel-level rootkit capabilities for Linux and Bring Your Own Vulnerable Driver (BYOVD) techniques for Windows. These capabilities allow the attackers to effectively blind EDR solutions such as CrowdStrike and SentinelOne by unlinking kernel callbacks. Their ability to blend exfiltration traffic with legitimate cloud-based configuration services further complicates detection and forensic analysis.













