Chinese hackers use AI to automate attacks on 170,000 servers

A Chinese-speaking cybercrime group, UAT-10147, is utilizing AI-assisted tools to automate attacks on over 170,000 servers globally. The group integrates AI for exploit validation and script generation to compromise Windows and Linux systems for data theft and SEO fraud.
Why it matters
This demonstrates the increasing sophistication of cyber threats as malicious actors adopt generative AI to scale and automate their operations.
X LinkedIn Reddit Facebook Share A Chinese-speaking cybercrime group is using AI-assisted tooling to automate attacks against vulnerable Windows and Linux web servers worldwide.
Tracked as UAT-10147 by Cisco Talos , the threat group targets internet-facing servers for data theft and search engine optimization (SEO) fraud, combining publicly available exploits, offensive security frameworks, custom malware, and increasingly sophisticated AI-generated attack workflows.
Talos researcher Joey Chen said the activity was discovered in early 2026 after investigators observed a compromised system communicating with a download server. An operational-security mistake left the server's directory publicly accessible, exposing malware, scripts, tooling, and a target list containing roughly 170,000 URLs.
The targets included government agencies, universities, media organizations, technology companies, and gaming businesses in countries including Brazil, Bolivia, China, Canada, and Vietnam.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in