Chinese Cybercrime Group Uses AI to Supercharge Attacks on Web Servers
Security researchers have uncovered a cybercrime group, tracked as UAT-10147, that is targeting Windows and Linux web servers across the education, media, technology, and gaming sectors. Businesses in Brazil, Bolivia, China, Canada, and Vietnam appear to be the most affected, though the group's methods suggest a broader global reach is possible.
The group has been observed using AI to help scale their attacks, alongside sophisticated tools designed to evade detection. This includes malware capable of bypassing endpoint detection and response (EDR) security software, as well as a Linux rootkit that can hide malicious activity deep within infected systems. These techniques make it harder for standard security tools to spot an intrusion before real damage is done.
While the campaign has primarily hit larger organisations so far, the use of AI to scale attacks is a warning sign for businesses of all sizes. Attackers increasingly rely on automation to identify vulnerable servers faster and deploy malware more efficiently, meaning smaller businesses with exposed or outdated servers could become easier, opportunistic targets.