Chinese-speaking crew UAT-10147 hits web servers with AI-built tools and a Linux rootkit
The group targets Windows and Linux servers across education, media, tech and gaming, with victims concentrated in Brazil, Bolivia, China, Canada and Vietnam.

Key points
- Researchers have named a new Chinese-speaking cybercrime group, UAT-10147, that is breaking into Windows and Linux web servers around the world.
- The group hits education, media, technology and gaming organisations, with most victims in Brazil, Bolivia, China, Canada and Vietnam.
- The crew uses a custom toolkit called SPECTRE, along with a Linux rootkit, meaning hidden software that gives attackers deep control of a machine.
- The gang appears to be using AI tools to help write and scale its attacks, according to reporting by The Hacker News.
- Investigators uncovered the activity after finding an exposed server the attackers had left open on the internet.
A new cybercrime crew has been caught breaking into web servers on a global scale, and it looks like they had some help from AI.
Security researchers are tracking the group as UAT-10147: Chinese-speaking, financially motivated. Unusually busy for a gang most people hadn't heard of a month ago.
The victims sit across education, media, technology and gaming. Most of the hacked servers are in Brazil, Bolivia, China, Canada and Vietnam, though the campaign reaches further.
Who are UAT-10147?
UAT-10147 is the label researchers gave a Chinese-speaking cybercrime group that attacks internet-facing web servers rather than individual laptops. First reported by The Hacker News, the crew hits both Windows and Linux machines, which is unusual: most gangs pick one platform and stick with it.
Investigators found the group after stumbling on an open server the attackers had left exposed on the public internet. It held tools, configuration files and clues about who they'd already compromised.
They don't look like a ransomware outfit chasing headlines. The pattern suggests long-term server access: rented out to other criminals, used for cryptocurrency mining, or both. We covered a comparable Chinese-speaking crew targeting Central Asian governments with two new malware families on 31 July, and the operational quietness here rhymes with that campaign.
How do the attacks work?
The hackers break into web servers, install a custom toolkit called SPECTRE, then conceal themselves with a Linux rootkit. A rootkit buries itself deep in the operating system so normal security tools don't see it running.
SPECTRE is built to slip past EDR, short for Endpoint Detection and Response, the modern security layer most organisations rely on to spot intruders. If the EDR can't see the attacker, the attacker gets to stay.
On Linux, the rootkit hooks into low-level system functions so that when an administrator lists running processes or open network connections, the malicious ones are quietly filtered out. It's a neat trick, and it works until you look at the right layer.
MFA wouldn't have stopped most of this. These are server-side break-ins exploiting unpatched web applications and admin panels left open to the internet, not credential theft via phishing.
Where does AI come in?
Researchers say UAT-10147 appears to be using AI coding assistants to write and refine parts of its malware, letting a small team produce more polished tools faster. The AI isn't doing the hacking. It's handling the boilerplate so the humans can focus on the parts that matter.
That matches a broader pattern this year: smaller crews scaling up quickly because a chatbot absorbs the dull work.
| Detail | What we know |
|---|---|
| Group name | UAT-10147 |
| Language | Chinese-speaking |
| Targets | Web servers, Windows and Linux |
| Sectors | Education, media, tech, gaming |
| Top victim countries | Brazil, Bolivia, China, Canada, Vietnam |
| Key tools | SPECTRE toolkit, Linux rootkit |
Should you worry if you run public-facing servers?
Yes. Patch your web software, lock admin interfaces so they're not reachable from the open internet, and confirm your EDR is actually reporting from every server, not just the desktops.
On Linux, watch for processes or network connections that appear in low-level logs but not in standard admin commands. That mismatch is the rootkit's fingerprint.
If a server seems fine but is a little too quiet, look harder.



