Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Chinese Hackers Use AI Agents to Automate Web Server Attacks
August 21, 2026
Agent Tesla Malware Hides in Unicode Emojis to Evade Detection
August 21, 2026
Critical GitLab Code Injection Flaw CVE-2023-5006 Actively Exploited
August 21, 2026
Home/Threats/Chinese Hackers Use AI Agents to Automate Web Server Attacks
Threats

Chinese Hackers Use AI Agents to Automate Web Server Attacks

Key Takeaways A Chinese-speaking threat actor, UAT-10147, is leveraging AI agents to automate and scale attacks against vulnerable web servers. The group targets internet-facing Windows and Linux...

Sarah simpson
Sarah simpson
August 21, 2026 4 Min Read
2 0

Key Takeaways

  • A Chinese-speaking threat actor, UAT-10147, is leveraging AI agents to automate and scale attacks against vulnerable web servers.
  • The group targets internet-facing Windows and Linux systems across government, education, media, technology, and gaming sectors.
  • Attacks exploit known remote code execution (RCE) vulnerabilities in products like Zimbra, AjaxPro, Nacos, and Telerik.
  • AI tools are used throughout the attack lifecycle, from initial scanning and exploit generation to post-compromise actions and persistence, significantly increasing attack speed and efficiency.
  • Defenders must prioritize rapid patching, reduce attack surface, and enhance monitoring of web server activity to mitigate these automated threats.

Chinese Hackers Automate Web Server Exploitation with AI Agents

A sophisticated Chinese-speaking cybercrime group is employing AI-assisted tools to transform vulnerable web servers into critical compromise points, according to recent findings. This development highlights how established security flaws become significantly more dangerous when attackers integrate automation, particularly through agent-like AI, into their operational workflows.

Table Of Content

  • Key Takeaways
  • Chinese Hackers Automate Web Server Exploitation with AI Agents
  • AI as an Operational Assistant
  • Automation Extends the Damage
  • What You Should Do

The threat group, identified as UAT-10147, has systematically targeted internet-facing Windows and Linux systems across diverse sectors, including government, education, media, technology, and gaming. Victims have been detected in various countries, with a command-and-control server revealing a staggering target list containing approximately 170,000 URLs.

Cisco Talos, a prominent cybersecurity research team, uncovered this activity, observing that the attackers ingeniously combine publicly available exploits with AI-generated instructions, custom scripts, and validation procedures. As Cisco Talos said in a report, this innovative approach enables the group to execute complex intrusions with unprecedented speed and scale. The primary concern isn’t merely the discovery of new vulnerabilities, but rather the dramatic acceleration of the entire attack process.

AI’s integration allows operators to automate tasks such as site scanning, adapting failed exploits, verifying payload execution, collecting system intelligence, and establishing backdoors with minimal manual intervention. This represents a tangible shift in the operational strategies of modern cybercriminal organizations.

AI as an Operational Assistant

UAT-10147 appears to utilize AI in an agent-like capacity, functioning as a comprehensive operational assistant rather than a singular, fully autonomous tool. Talos researchers discovered AI-generated playbooks, troubleshooting logic, exploit scripts, and validation workflows that support activities both before and after a server compromise. This indicates a deep integration of AI across multiple stages of their attack chain.

The group merges these AI-powered workflows with established offensive frameworks, allowing them to efficiently identify weaknesses, construct payloads, test results, and document subsequent actions. This sophisticated blend underscores broader concerns within the cybersecurity community regarding the security implications and risks associated with AI agents in malicious hands.

Initial access for these attacks frequently capitalizes on well-known remote code execution (RCE) vulnerabilities. The campaign has exploited flaws in popular applications such as Zimbra, AjaxPro, Nacos, and Telerik. This serves as a stark reminder that unpatched or misconfigured web server RCE vulnerabilities offer a direct and often swift path to complete system takeover.

For Windows targets, the attackers leveraged remote access to install BadIIS, a malicious IIS module known for manipulating search results. They also deployed scripts designed to escalate privileges, disable endpoint security scanning around critical IIS folders, create high-privilege access, and maintain persistent control following the initial breach.

Linux systems experienced a similar attack pattern. After successfully deploying a web shell, the group exploited local privilege-escalation vulnerabilities, including the notorious Dirty Pipe flaw, to gain root access and install additional persistent implants.

Automation Extends the Damage

The forensic evidence recovered suggests that AI played a crucial role throughout the entire attack lifecycle, extending far beyond mere code generation. One particular AI-generated guide provided a structured methodology for exploiting ASP.NET ViewState deserialization, encompassing steps from verifying stolen configuration keys to crafting payloads and confirming their execution without leaving obvious visual traces.

These automated scripts were observed checking for writable directories, mapping IIS sites, deploying implants, installing web shells, and collecting results via callbacks. Critically, the workflow is designed to be resilient; a failed attack does not necessarily halt the operation. Instead, the AI-driven workflow can diagnose the obstacle and attempt alternative methods, enhancing the attacker’s persistence and success rate.

Talos also noted the group’s use of a cloud configuration service to gather basic victim details after exploiting Nacos. By interweaving stolen information with seemingly routine web traffic, attackers can make their initial reconnaissance and subsequent malicious activities more challenging for defenders to detect.

What You Should Do

  • Prioritize Patching: Immediately apply security updates and patches for all public-facing web servers and applications, especially those known to have RCE vulnerabilities (e.g., Zimbra, AjaxPro, Nacos, Telerik).
  • Reduce Attack Surface: Limit unnecessary exposure by closing unused ports, disabling unneeded services, and implementing strict network segmentation.
  • Review Configurations: Regularly audit and review IIS and application configurations for any unauthorized changes or weak settings. Pay close attention to ASP.NET MachineKey protection.
  • Enhanced Monitoring: Implement robust logging and monitoring for unusual scheduled tasks, new user accounts, outbound connections from web servers, and modifications to security exclusion paths.
  • Investigate Errors: Do not dismiss unexpected server errors as benign noise. Investigate them thoroughly, as they can reveal attacker testing, particularly for deserialization vulnerabilities.
  • Protect Administrative Endpoints: Tightly restrict access to administrative interfaces and deployment endpoints for web servers and applications.
  • Maintain Asset Inventory: Keep an up-to-date inventory of all public-facing assets to ensure comprehensive patching and monitoring coverage.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Agent Tesla Malware Hides in Unicode Emojis to Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
US Bank Investigates LockBit Ransomware Attack Claiming Data Theft
August 21, 2026
Critical N-able Passportal Flaw Exposes Password Vaults, 2FA Codes
August 21, 2026
Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us