ALITEQ.

A hacking crew's exploit notes were written by AI and that should worry you more than the hack itself

Cisco Talos caught a Chinese-speaking group using AI to write its playbooks against 170,000 targets. The scary part isn't the bugs — it's that all of them are old and already patchable.

Lena FischerUpdated 1h ago8 min readWeb story
A hooded figure at a laptop in a dark room, illustrating the cybercrime operations Cisco Talos attributes to UAT-10147

Cisco Talos has been tracking a Chinese-speaking cybercrime group since early 2026 that it calls UAT-10147, and the detail that matters isn't which servers it's broken into. It's what Talos found sitting next to the exploit code: AI-generated playbooks — prerequisite checklists, validation steps, troubleshooting notes — written for the attackers, by an AI, to make attacks that used to require real expertise runnable by almost anyone on the team.

The bugs aren't new. That's the actual story

Here's the detail that should reframe how you read this: none of UAT-10147's initial-access exploits are zero-days. Talos observed them using CVE-2022-27925 (a Zimbra RCE), CVE-2021-23758 (AjaxPro deserialization), CVE-2021-29441 and CVE-2021-29442 (Nacos framework RCE), and CVE-2019-18935 (Telerik UI deserialization) to get in. For privilege escalation on Linux boxes, the toolkit reaches back even further — CVE-2021-3156 (the "Baron Samedit" sudo buffer overflow), CVE-2022-0847 (Dirty Pipe), and bugs from 2015 and 2010 that most security teams assumed were irrelevant folklore by now.

The exploit stack — all old, all patchable

Initial access

Stage
CVE-2022-27925, CVE-2021-23758, CVE-2021-29441/29442, CVE-2019-18935
CVEs used
3–7 years old

Privilege escalation

Stage
CVE-2021-3156, CVE-2022-0995, CVE-2022-0847, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904
CVEs used
4–16 years old

What the AI is actually doing

Talos assessed with moderate-to-high confidence that UAT-10147 is part of an emerging class of financially motivated actors weaponizing agentic AI for post-compromise work specifically — not to find new vulnerabilities, but to make old ones profitable at a scale a small crew couldn't hit manually. The researchers described the AI's role as "iterative exploit refinement, adaptive troubleshooting, post-exploitation automation, exploit validation workflows, operational documentation generation." In plain terms: the AI writes the runbook, checks whether an exploit actually worked, and tells a less-skilled operator what to try next if it didn't.

My honest take

The instinct with a story like this is to treat AI as the villain, but the honest read is that AI is a force multiplier on a problem that already existed: a huge population of internet-facing servers running software with patches available since 2019, 2021, 2022. UAT-10147 didn't need a novel technique. It needed a target list, some scripting, and a way to run the same well-known exploits against 170,000 URLs without hiring 170,000 hours of skilled labor. Agentic AI is what closed that labor gap, which is exactly the finding that should worry defenders more than a fancy new zero-day would — it means the entry cost for scaled, competent attacks against unpatched infrastructure just dropped for a lot of groups that couldn't previously afford it. This isn't dissimilar to the pattern behind the recent LiteLLM/Trivy supply-chain incident that quietly reached 2,500 companies — scale through automation, not through novelty.

Check whether any internet-facing Zimbra, Nacos, Telerik UI, or AjaxPro instances in your environment are still on the versions vulnerable to the CVEs above — these are the specific doors UAT-10147 walks through.

On Linux servers, confirm sudo, kernel and systemd packages are patched against Baron Samedit (CVE-2021-3156) and Dirty Pipe (CVE-2022-0847) specifically — both remain in this group's active toolkit years after disclosure.

Watch for Meterpreter, QuasarRAT, NoodleRAT or the cross-platform SPECTRE implant in EDR alerts — Talos ties all four to this actor's post-compromise stage.

Don't assume an old CVE is a low-priority patch just because it's old — this campaign is proof that age has stopped correlating with irrelevance.

What does UAT-10147 actually want — data, ransom, or something else?
Financial gain through SEO fraud and data theft, per Talos's assessment. This isn't a ransomware crew or a state-sponsored espionage operation in the classic sense — it's closer to organized cybercrime optimizing for volume.
Is this the first time AI has been used this way in an attack?
No, but Talos frames it as part of an emerging pattern among financially motivated groups specifically, distinct from earlier reports of AI-assisted attacks by state-linked actors. The scale — 170,000 targets — is what stands out.
If all the CVEs are old, why hasn't everyone patched them already?
Because "old" and "patched everywhere" aren't the same thing. Internet-facing legacy servers, forgotten test instances, and software nobody's inventoried are exactly what a target list of 170,000 URLs is built to find — patch coverage on paper doesn't mean patch coverage in practice.
Does this mean AI tools like PentestGPT are inherently malicious?
No — PentestGPT and similar tools are built for legitimate penetration testing. UAT-10147 repurposing them for unauthorized attacks is a misuse-of-dual-use-tooling problem, the same category as Metasploit or Cobalt Strike being used by both defenders and attackers.

The uncomfortable forward-looking read here is that this is the floor, not the ceiling. UAT-10147 is using agentic AI to industrialize attacks with publicly known, years-old vulnerabilities — it hasn't needed a zero-day yet. When a group like this does pair the same automation with a genuinely novel bug, the scale problem gets a lot worse a lot faster than most patch cycles are built to handle. Inventory your internet-facing legacy software this week. It's the cheapest defense against a threat model that's explicitly built around exactly that gap.

AI & Local Compute Editor

Lena Fischer

Lena runs more GPUs at home than she'll admit to and has quantized more models than she's finished reading about. She writes about running AI on your own hardware — what actually fits, what's genuinely fast, and what the polished cloud demos quietly leave out.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading