Cisco Talos Ties Chinese-Speaking UAT-10147 Group to 170k-Server Campaign Using PentestGPT and DeepAudit
Summary
Cisco Talos disclosed on Aug 24 that a Chinese-speaking crew it tracks as UAT-10147 is using AI coding assistants including PentestGPT and DeepAudit to scale intrusion operations against Windows and Linux web servers. An exposed operator directory revealed a target list of roughly 170,000 URLs across governments, universities, media and gaming companies in the US, India, UK, Germany and the Netherlands. The group's SPECTRE C backdoor supports 45 commands on Windows and installs a companion kernel rootkit on Linux, using BYOVD techniques to disable CrowdStrike Falcon and Microsoft Defender.
Originally reported by thehackernews.com
Read the original article →Original headline: Cisco Talos Ties Chinese-Speaking UAT-10147 Group to 170k-Server Campaign Using PentestGPT and DeepAudit