Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ai-assisted-attacks (1 article)Clear

Crime group uses AI to mass-hack servers and deploy a Linux rootkit backdoor

Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.

Check
Patch internet-facing web servers promptly since the group exploits known flaws at scale, enforce protections that block unsigned driver loads, and deploy endpoint detection with kernel-level visibility on Windows and Linux.
Affected
Organizations running internet-facing IIS or Linux web servers with unpatched known vulnerabilities; the group gains access at scale, deploys a rootkit and cross-platform backdoor, disables endpoint detection, and steals credentials and data.
Fix
Prioritize patching exposed servers, enable hypervisor-protected code integrity to counter driver-based evasion, monitor east-west traffic from web servers to internal Linux hosts, and hunt for kernel rootkits and unexpected HTTPS beacons.