Chinese-Speaking Hackers Deploy AI to Automate Attacks After Breaching Web Servers
Cisco Talos researchers have identified a Chinese-speaking cybercrime group, tracked as UAT-10147, that is compromising vulnerable web servers across multiple countries. What makes this campaign notable is the group's use of agentic AI—automated tools capable of making decisions and carrying out tasks with limited human input—to manage activities after they've gained access to a system.
The attackers use malware known as BadIIS to infect servers running Microsoft's Internet Information Services (IIS) software, a common platform for hosting websites. Once inside, the group leverages AI-driven automation to carry out post-compromise operations more efficiently, potentially allowing them to scale attacks and adapt tactics faster than traditional manual methods would allow.
While the full scope of impact is still being assessed, the use of agentic AI by threat actors signals an evolving trend in cybercrime. As attackers begin integrating AI into their toolkits, businesses running web servers—especially IIS-based systems—should be aware that compromises may now unfold faster and with greater sophistication than before.