UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking adversary has launched AI-driven cyberattacks on a massive scale.
Evidence dossier
Intelligence passport
Measured timeline
- Detected The first matching coverage entered the Archynetys cluster.
- Peak measured velocity The recorded velocity reached 14.
- Evidence threshold reached The story had enough independent coverage for an explanatory brief.
- Latest coverage observed Most recent article currently attached to this story cluster.
Source diversity sample: Investing.com · Bloomberg.com · gbhackers.com · CyberInsider · cyberpress.org · Cisco Talos Blog · The Hacker News.
How this dossier is built: methodology · AI policy · corrections.
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
What happened
170,000 servers have been targeted in a cyberattack campaign using AI to automate vulnerability exploitation. The campaign, attributed to a Chinese-speaking adversary, employs DeepSeek and Hermes Agent to launch autonomous cyberattacks.
The Hacker News, Cisco Talos Blog and GBHackers.com all agree that the attack uses SPECTRE with EDR bypass and a Linux rootkit. The Hacker News and Cisco Talos Blog both name the adversary UAT-10147.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 9h ago.
Sources (8)
- Chinese hackers use DeepSeek AI to boost attacks Investing.com · 13h ago
- Chinese Hackers Use DeepSeek to Boost Attacks, Researchers Say Bloomberg.com · 13h ago
- Chinese Hackers Use DeepSeek to Boost Attacks, Researchers Say Bloomberg.com · 13h ago
- Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks gbhackers.com · 13h ago
- Chinese hackers use AI to automate attacks on 170,000 servers CyberInsider · 13h ago
- Chinese Hacker Uses DeepSeek AI to Automate Vulnerability Exploitation cyberpress.org · 13h ago
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Cisco Talos Blog · 13h ago
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Hacker News · 13h ago
Questions people are asking
What is the name of the adversary?
The Hacker News and Cisco Talos Blog both name the adversary UAT-10147.
What tools are being used in the attack?
The attack uses DeepSeek and Hermes Agent to launch autonomous cyberattacks. The attack uses SPECTRE with EDR bypass and a Linux rootkit.
How many servers have been targeted?
170,000 servers have been targeted.
Topics
Related trends
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
A vulnerability in Microsoft Defender's driver can be exploited to disable security software, raising concerns for cybersecurity professionals.
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
A new Spectre attack method has been demonstrated against Cloudflare Workers, extracting sensitive data at unprecedented speeds.
US warns Siemens devices can be hacked amid fears Iran is breaching water plants
The U.S. government has issued a warning about AI-driven cyberattacks targeting Siemens industrial controls at water plants.
OpenAI introduces a new cyber model amid fears of AI cyberattacks
OpenAI's new cybersecurity model launches amid growing concerns over AI-driven cyber threats.
DeepSeek's new AI model is by far the cheapest of well-known models to run, research firm says
DeepSeek's new AI model is the cheapest to run among well-known models, but it's not the only factor driving AI's race to zero.
DeepSeek’s Normally Boring CEO Is Reportedly Spiraling After Supposed Leak
DeepSeek halts its funding round after a leaked philosophy piece sparks US‑China controversy and CEO unrest.
Open prediction lab
Can you beat the machine?
Pick tomorrow's top trend, then compare your result with Archynetys's self-graded forecast.
📬 The daily trend digest
The world's top trends, once a day. No spam, one-click unsubscribe.