UAT-10147 uses AI to automate cyberattacks on web servers

 

UAT-10147 uses AI to automate cyberattacks on web servers

Cisco Talos has discovered a threat actor known as UAT-10147 targeting Windows and Linux web servers around the world. The campaign has affected organizations in government, education, media, technology and gaming, with many targets located in Brazil, Bolivia, China, Canada and Vietnam.

The attackers used publicly known vulnerabilities to gain access and leveraged AI-powered tools for reconnaissance, exploit development, troubleshooting, payload creation, validation and persistence. The tools include Metasploit, ysoserial, PentestGPT and DeepAudit, as well as several privilege escalation exploits.

The campaign involved the exploitation of vulnerabilities in products such as Zimbra, AjaxPro, Telerik UI for ASP.NET AJAX and Alibaba Nacos. Some of the CVEs used by the attackers include CVE-2022-27925, CVE-2021-23758, CVE-2019-18935, CVE-2021-29441 and CVE-2021-29442.

On Linux systems, UAT-10147 also used known local privilege escalation flaws, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904 and CVE-2022-0847, to obtain root access.

The campaign came to light after researchers discovered an exposed directory linked to a compromised machine. It contained a list of about 170,000 URLs, which the attackers divided into smaller files for automated processing. After gaining access, they deployed malware for SEO fraud and data theft, including BadIIS, Noodle RAT, SPECTRE and Meterpreter.


Back to the list