Skip to content
Auto-CTI
Back to today
UAT-10147 CRITICAL B3

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

B Cisco Talos Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

For the first time, an APT actor is documented systematically using agentic AI tooling (playbooks, exploit automation, payload generation) across the entire post-compromise lifecycle, significantly increasing the speed and scalability of intrusions.

Description

Cisco Talos describes the Chinese-speaking actor UAT-10147, which attacks internet-exposed Windows and Linux web servers worldwide and uses publicly known vulnerabilities for initial access at scale. Compromise occurs among others via CVE-2019-18935, a .NET JSON deserialization flaw in Telerik UI for ASP.NET AJAX that allows remote code execution. After gaining a foothold, open-source frameworks such as Metasploit, ysoserial, PentestGPT and DeepAudit along with several privilege escalation exploits are used; a multi-stage script downloads a privilege escalation tool (EfsPotato), a secondary batch script and a QuasarRAT payload disguised as svchosts.exe via certutil. Notable is the integration of agentic AI components for reconnaissance, exploit validation, payload generation and persistence, including AI-generated operational playbooks and troubleshooting logic. The activity targets organizations in government, education, media, technology and gaming; no attribution to a known grouping is made, and ClamAV and Snort signatures for detection are available.

Risk score

80
strategic relevance
0.85
consensus penalty
-5.00

Path: strategic

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • VENDOR_MISMATCH Vendor not found in alert title −5
Consensus penalty:
−5.0
Total penalty:
−5.0
ESC