UAT-10147 global web-server intrusion campaign
Campaign
Summary
Hide ▲
Show ▼
The UAT-10147 campaign is actively targeting Windows and Linux web servers worldwide, using publicly disclosed vulnerabilities to gain initial access and maintain persistence across multiple sectors. The activity raises risk for organizations in education, media, technology, and gaming, with observed focus across Brazil, Bolivia, China, Canada, and Vietnam. Operators are pairing AI-assisted tooling with exploit frameworks and post-exploitation implants to scale intrusion and data-theft operations.
Related Happenings
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignAbout this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
Campaign
H score36
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
CampaignAbout this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Timeline
-
24.08.2026 11:08 2 articles · 12h ago
UAT-10147 targets Windows and Linux web servers worldwide
Initial DisclosureCisco Talos disclosed a Chinese-speaking cybercrime group dubbed UAT-10147 that is targeting Windows and Linux web servers across education, media, technology, and gaming, with the largest concentration in Brazil, Bolivia, China, Canada, and Vietnam. The operators are using publicly disclosed vulnerabilities for initial access and combining Metasploit, ysoserial, PentestGPT, DeepAudit, web shells, BadIIS, Quasar RAT, and SPECTRE with AI-assisted workflows to automate exploitation, persistence, SEO fraud, data theft, and EDR bypass.
Show sources
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit — thehackernews.com — 24.08.2026 11:08
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit — thehackernews.com — 24.08.2026 11:08