Threat Intelligence

Chinese Cybercrime Group Uses AI to Supercharge Attacks on Web Servers

The Hacker News · 24 Aug 2026
Key Takeaway Keep all internet-facing servers patched and monitored, as attackers are increasingly using AI to find and exploit vulnerable systems faster than ever.

Security researchers have uncovered a cybercrime group, tracked as UAT-10147, that is targeting Windows and Linux web servers across the education, media, technology, and gaming sectors. Businesses in Brazil, Bolivia, China, Canada, and Vietnam appear to be the most affected, though the group's methods suggest a broader global reach is possible.

The group has been observed using AI to help scale their attacks, alongside sophisticated tools designed to evade detection. This includes malware capable of bypassing endpoint detection and response (EDR) security software, as well as a Linux rootkit that can hide malicious activity deep within infected systems. These techniques make it harder for standard security tools to spot an intrusion before real damage is done.

While the campaign has primarily hit larger organisations so far, the use of AI to scale attacks is a warning sign for businesses of all sizes. Attackers increasingly rely on automation to identify vulnerable servers faster and deploy malware more efficiently, meaning smaller businesses with exposed or outdated servers could become easier, opportunistic targets.

cybercrime AI threats server security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.