
Cisco Talos researchers identified a cybercrime group, UAT-10147, using artificial intelligence to automate attacks on approximately 170,000 internet-facing Windows and Linux servers worldwide.
The group exploits vulnerabilities in software like Zimbra and Telerik UI to deploy custom malware, including a Linux rootkit named Specter that researchers believe was built with AI assistance.
The campaign, active since early 2026, targets government agencies and technology firms across countries including Brazil, China, and Vietnam to facilitate data theft and SEO fraud.