Actor Profile

UAT-10147 is a Chinese-speaking cybercrime group conducting large-scale attacks against Windows and Linux web servers globally. The actor's primary motivation appears to be SEO fraud and data theft. UAT-10147 distinguishes itself through integration of AI-powered tools (PentestGPT, DeepAudit) throughout the attack lifecycle to automate exploitation, reconnaissance, payload generation, and validation at scale. The group demonstrates advanced operational maturity by splitting target lists of ~170,000 URLs into manageable chunks and leveraging legitimate cloud infrastructure (Nacos) for asynchronous data exfiltration to blend with normal administrative traffic.

TTPs (Tactics, Techniques, Procedures)

Initial Access: Exploits known vulnerabilities including CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI), CVE-2021-29441/29442 (Alibaba Nacos) for remote code execution on web servers. Execution: Deploys web shells, uses certutil for payload download, executes batch scripts. Privilege Escalation: Leverages EfsPotato and multiple Linux LPE exploits (CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, CVE-2022-0847). Defense Evasion: Configures Microsoft Defender exclusions, deletes initial payloads, uses SPECTRE malware with EDR bypass capabilities. Persistence: Establishes deceptive scheduled tasks ("Google Chrome Start"), deploys multiple backdoors (BadIIS, Gh0stCringe, Quasar RAT, Noodle RAT, Rekoobe, SPECTRE, Meterpreter). Command and Control: Routes exfiltration through legitimate Nacos cloud service to blend with administrative traffic. Discovery/Reconnaissance: Uses AI frameworks (PentestGPT, DeepAudit) for vulnerability scanning and automated exploitation.

Targets & Patterns

UAT-10147 primarily targets the education, media, technology, and gaming sectors with a global reach. Victim concentration is highest in Brazil, Bolivia, China, Canada, and Vietnam, though target lists indicate broader scanning activity across the U.S., India, U.K., Germany, and Netherlands. The actor targets both Windows (IIS servers) and Linux web servers, suggesting opportunistic targeting based on vulnerability exposure rather than highly selective victim profiling. The use of ~170,000 URL target lists indicates mass exploitation at scale, consistent with the group's SEO fraud and data theft objectives. The choice of sectors suggests targeting organizations with high web traffic value for SEO manipulation and potentially valuable data assets.

Historical Context

UAT-10147's use of BadIIS malware links the group to a broader ecosystem of Chinese-speaking cybercrime actors. The specific BadIIS variant deployed operates under a malware-as-a-service (MaaS) model and is shared among multiple Chinese-speaking cybercrime groups, indicating UAT-10147 participates in or leverages established Chinese cybercrime infrastructure. The discovery came through analysis of an exposed directory at 139.180.197[.]150 communicating with compromised machines. The integration of AI-powered offensive tools (PentestGPT, DeepAudit) represents an evolution in cybercrime tradecraft, with UAT-10147 among the first observed actors systematically incorporating AI throughout the attack chain for scaling operations.

Defensive Recommendations

  • Prioritize patching CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI), CVE-2021-29441/29442 (Alibaba Nacos), and Linux LPE vulnerabilities CVE-2022-0995, CVE-2021-3156, CVE-2022-0847 which are actively exploited by UAT-10147
  • Monitor for certutil.exe abuse (T1105) downloading executables, particularly EfsPotato privilege escalation tools, and detect suspicious Defender exclusion modifications via Windows Event Logs
  • Inspect scheduled tasks for persistence mechanisms using deceptive names (e.g., 'Google Chrome Start') and audit for unauthorized tasks executing from user-writable directories
  • Implement network monitoring for outbound connections to Alibaba Nacos or similar cloud configuration management services that may indicate asynchronous data exfiltration blending with legitimate traffic
  • Deploy behavioral detection for SPECTRE malware's EDR bypass capabilities and Linux rootkit functionality, focusing on anomalous process injection, kernel module loading, and hidden process detection

---

# Geopolitical Context

Geopolitical Context

UAT-10147 represents an evolution in Chinese-language cybercrime operations, demonstrating the integration of artificial intelligence frameworks into traditional financially-motivated intrusion campaigns. The group's deployment of AI-assisted tools—including PentestGPT and DeepAudit—for vulnerability scanning, exploit refinement, and operational automation signals a broader trend in which commodity cybercrime actors adopt capabilities previously associated with state-sponsored advanced persistent threats. The targeting of education, media, technology, and gaming sectors across Brazil, Bolivia, China, Canada, and Vietnam suggests opportunistic rather than strategic victim selection, consistent with SEO fraud and data theft monetization models. The use of BadIIS malware-as-a-service infrastructure indicates participation in a mature Chinese-language cybercrime ecosystem with shared tooling and commercial relationships. While the actor's linguistic profile and toolchain overlap with China-nexus threat activity, the campaign's financial motivation and indiscriminate global targeting distinguish it from intelligence collection operations typically attributed to state-aligned groups.

State Actor Alignment

UAT-10147 is assessed to be a financially-motivated cybercrime group rather than a state-sponsored actor, despite Chinese-language operational indicators. The group's reliance on malware-as-a-service platforms such as BadIIS—known to serve multiple Chinese-speaking cybercrime groups—and focus on SEO fraud and data theft are consistent with profit-driven activity. No evidence currently links UAT-10147 to Chinese state interests or intelligence priorities. The campaign does not appear to fall under existing sanctions frameworks targeting state-sponsored cyber operations, though the exploitation of servers in multiple jurisdictions may trigger law enforcement coordination through mechanisms such as Interpol or bilateral cybercrime working groups. The group's infrastructure and tooling overlap with the broader Chinese-language cybercrime ecosystem but lack the targeting discipline, operational security, or strategic objectives characteristic of state-directed campaigns.

Business Impacty pro region

The campaign's global footprint—with significant victim concentrations in Latin America (Brazil, Bolivia), Asia-Pacific (China, Vietnam), and North America (Canada)—underscores the transnational nature of modern cybercrime infrastructure. For Europe, the targeting list includes substantial numbers of potential victims in the United Kingdom, Germany, and the Netherlands, indicating exposure across critical sectors including education and technology. The exploitation of widely deployed enterprise software (Zimbra, Telerik UI, Alibaba Nacos) poses supply chain and third-party risk for organizations across the European Union and NATO member states. The group's use of legitimate cloud infrastructure for command-and-control and data exfiltration complicates detection and attribution efforts for national cybersecurity agencies. The campaign may prompt renewed attention to vulnerability management and patch cadence in sectors with limited cybersecurity resources, particularly education institutions. The AI-assisted scaling of attacks suggests that even mid-tier cybercrime actors can now achieve operational tempo previously requiring significant human resources, potentially straining incident response capacity across affected regions.

Forecast

If UAT-10147 continues to refine its AI-assisted exploitation workflows, the group is likely to increase both the velocity and scale of compromises, potentially expanding victim counts beyond the current 170,000-URL target list. Should the threat actor operationalize DeepAudit for zero-day or N-day vulnerability discovery within victim environments, the campaign may shift from opportunistic exploitation to more targeted intrusions with higher-value data theft outcomes. If law enforcement agencies coordinate takedown operations targeting the BadIIS malware-as-a-service infrastructure, UAT-10147 may migrate to alternative implant families or develop proprietary tooling, temporarily disrupting but not eliminating the threat. The demonstrated use of cross-platform SPECTRE malware with EDR bypass and Linux rootkit capabilities suggests the group may increasingly target cloud and containerized environments in coming months. If other cybercrime groups adopt similar AI-augmented tradecraft, defenders should anticipate a broader shift toward automated, high-volume intrusion campaigns that challenge traditional detection and response models.