{"id":26173,"date":"2026-09-21T15:13:04","date_gmt":"2026-09-21T23:13:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/agentic-ai-scales-semiautonomous-server-attacks\/"},"modified":"2026-09-21T15:13:04","modified_gmt":"2026-09-21T23:13:04","slug":"agentic-ai-scales-semiautonomous-server-attacks","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/agentic-ai-scales-semiautonomous-server-attacks\/","title":{"rendered":"Agentic AI scales semiautonomous server attacks"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>A group of Chinese-speaking cybercriminals is using artificial intelligence to orchestrate malicious attacks on government, media, technology, and gaming organizations, a research report has found.<\/p>\n<p>Dubbed UAT-10147, the group is among an emerging class of financially motivated intrusion operators using AI systems to operationalize offensive tradecraft at scale, Cisco Talos threat intelligence group researchers said.<\/p>\n<p>Talos threat intelligence researcher Joey Chen <a href=\"https:\/\/blog.talosintelligence.com\/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations\/\"><span style=\"text-decoration:underline\">explained in an August 20 blog post<\/span><\/a> that, unlike the traditional use of generative AI for simple scripting assistance, UAT-10147 uses agentic AI for tasks such as:<\/p>\n<ul class=\"list-bullet\">\n<li class=\"\" value=\"1\">iterative exploit refinement;<\/li>\n<li class=\"\" value=\"2\">adaptive troubleshooting;<\/li>\n<li class=\"\" value=\"3\">post-exploitation automation;<\/li>\n<li class=\"\" value=\"4\">exploit validation workflows; and<\/li>\n<li class=\"\" value=\"5\">operational documentation generation.<\/li>\n<\/ul>\n<p style=\"padding-inline-start:40px\"><em>\u201cThis indicates a transition from AI-assisted scripting toward semiautonomous offensive orchestration.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/joey-chen-0873a797\/\"><span style=\"text-decoration:underline\">Joey Chen<\/span><\/a><\/p>\n<p>Here\u2019s what you need to know about this new semiautonomous AI attack method \u2014\u00a0and why developing an agentic security operations center (SOC) strategy is key to modern defense.<\/p>\n<p><strong>[ See webinar: <\/strong><a href=\"https:\/\/www.reversinglabs.com\/webinar\/autonomy-not-autopilot-agentic-soc-watch-now\"><strong>Autonomy, Not Autopilot: Get Real About the Agentic SOC<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"ai-developed-its-own-malicious-tools\">AI developed its own malicious tools<\/h2>\n<p>Cisco Talos first detected UAT-10147 early this year as the group targeted vulnerable web servers. The group was observed carrying out multiple criminal activities, including search engine optimization (SEO) fraud and data theft.<\/p>\n<p>Talos found that UAT-10147 was gradually incorporating AI-assisted development into its operations to support the creation and refinement of tools used across its campaigns. A custom-developed backdoor dubbed SPECTRE and a rootkit called Specter both exhibit indications of AI-assisted development, Talos said.<\/p>\n<p>The researchers noted that SPECTRE represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credentiasl theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.<\/p>\n<p>UAT-10147 demonstrated operational maturity through the combined use of custom malware, open-source offensive tooling, bring your own virtual driver (BYOVD)-based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.<\/p>\n<p>After analyzing recovered source code, the researchers also found that portions of the Linux rootkit development may have incorporated AI-assisted code-generation workflows, highlighting the growing role of generative AI in accelerating offensive malware development.<\/p>\n<p>UAT-10147\u2019s exploitation ecosystem demonstrates the power of agentic AI in the hands of malicious actors, said Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAgentic AI gives adversaries scale without proportional expertise.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/jacob-krell\/\"><span style=\"text-decoration:underline\">Jacob Krell<\/span><\/a><\/p>\n<p>Krell noted that UAT-10147 relied on publicly disclosed vulnerabilities, some more than a decade old, but had its AI generate a nine-section exploitation guide and four Python scripts to automate delivery, verification, and deployment \u2014 work that once required a senior operator to troubleshoot each target individually.\u00a0<\/p>\n<p>He stressed that one small cybercrime group was able to build a target list of roughly 170,000 URLs because the AI, rather than an experienced operator, handled the adaptive troubleshooting and validation each engagement used to demand.<\/p>\n<h2 id=\"agentic-ai-attack-analysis-post-compromise-damage-is-key\">Agentic AI attack analysis: Post-compromise damage is key<\/h2>\n<p>Post-compromise is where agentic AI does its most damage, said Aviv Nahum, co-founder and CEO of Above Security.<\/p>\n<p>Nahum said that once an attacker has a foothold, the job shifts to investigation: mapping the network, working out which credentials actually function, and deciding where to go next when the first attempt fails.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThat\u2019s an iterative, branching problem, and it is exactly what agents are built for.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/avivon\/\"><span style=\"text-decoration:underline\">Aviv Nahum<\/span><\/a><\/p>\n<p>Where a human operator has to work through those branches one at a time, he said, an agent can build or edit its own tooling on the fly, test a hypothesis, and keep pushing toward the objective without waiting on a person to greenlight the next step.<\/p>\n<p>Abu Bakr Q, director of cybercrime disruption for BforeAI, said the UAT-10147 group used AI not just to draft scripts, but also to generate full playbooks covering automated exploit validation, reconnaissance that \u201cphones home,\u201d and step-by-step guides from initial shell to persistence. That kind of automation, he said, is what makes the post-compromise phase \u201cfaster, more scalable, and harder to interrupt.\u201d<\/p>\n<p>Agentic AI not only accelerates attacks; it also collapses the expertise curve, said Josh Taylor, lead cybersecurity analyst at Fortra. In the UAT-10147 campaign, agentic tooling quickly generated a ViewState deserialization playbook, a token-impersonation privilege-escalation procedure, and three working deployment scripts \u2014 work that once required a team of operators with years of Windows internals experience.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cTradecraft can now be easily obtained by a good prompt query instead of earned over a career.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/josh-j-taylor\/\"><span style=\"text-decoration:underline\">Josh Taylor<\/span><\/a><\/p>\n<h2 id=\"fight-ai-with-ai-agentic-soc-is-essential\">Fight AI with AI: Agentic SOC is essential<\/h2>\n<p>To counter the threats posed by groups such as UAT-10147, organizations are fighting agentic AI with agentic AI. That gave rise to the idea of the agentic SOC.<\/p>\n<p>In an interview at the recent Black Hat security conference, Kanaiya Vasani, CPO and CMO at ExtraHop, told RL Blog that the standard SOC model as fundamentally batch-oriented: alerts arrive from detection and response systems as logs, which a Level 1 analyst triages and turns into cases before escalating to Level 2, and sometimes Level 3, for deeper investigation and proactive threat hunting. That entire cycle, he said, can take hours or even days.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIn the post-Mythos landscape, where you have AI-assisted attackers who can basically find a vulnerability and exploit it in seconds, this model is just not going to work.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/kanaiyavasani\/\"><span style=\"text-decoration:underline\">Kanaiya Vasani<\/span><\/a><\/p>\n<p>The agentic SOC represents a paradigm shift from batch processing to real-time operations, where telemetry is ingested continuously and behavioral detections fire the moment they trigger, Vasani said.<\/p>\n<p>Agents then bolt on to that detection pipeline \u2014 drawing on knowledge graphs and context they\u2019re already logged into \u2014 to finish an investigation and drive a response in near real time, whether with a human in the loop or fully autonomously. The result: a pipeline and workflow that executes end to end in minutes, not hours or days.<\/p>\n<h2 id=\"the-race-is-on-speed-up-your-soc-workflow\">The race is on: Speed up your SOC workflow<\/h2>\n<p>Security leaders anticipate that AI will handle approximately 60% of SOC workloads within the next three years, said <a href=\"https:\/\/www.linkedin.com\/in\/kdshah\/\"><span style=\"text-decoration:underline\">Kamal Shah<\/span><\/a>, CEO of Prophet Security. AI lets teams rapidly filter the noise created by legacy security tools, automate repetitive and tedious work, and spend more time on the parts of the job that still require human judgment \u2014 while shortening the time it takes to hand back an answer that clearly states scope, impact, affected assets, and next actions, backed by evidence the business can trust, he said.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/john-strand-a1b4b62\/\"><span style=\"text-decoration:underline\">John Strand<\/span><\/a>, a principal at Black Hills Information Security, said one of the biggest problems in an SOC is correlating and fusing logs from multiple sources: cloud services, SaaS platforms, endpoints, Active Directory, network traffic, and more.\u00a0<\/p>\n<p>In a traditional SOC, an analyst needs considerable time to fuse that information into an overall attack path, or even to identify what the attacker is after. AI greatly reduces the time defenders need to pull all of that together, Strand said.<\/p>\n<p>While Donald McFarlane, an advisory board member at Xcape, argues that agentic SOCs aren\u2019t necessary to counter agentic attacks, he acknowledges that defenders need some machine-speed detection and response to match attackers\u2019 operating speed. If an SOC still relies on analysts manually copying IP addresses between consoles and escalating tickets to other humans before any response action occurs, it\u2019s probably time for a change, he said.\u00a0<\/p>\n<p>There are plenty of things that can safely be automated \u2014 enrichment, correlation, hypothesis generation, repetitive investigation, and some containment \u2014 though high-consequence actions still need appropriate policy boundaries and, in many cases, human judgment.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cCyber defense has traditionally placed some reliance on attackers having limited time, limited people and limited attention. Agentic AI starts removing all three constraints.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/dmcfarlane\/\"><span style=\"text-decoration:underline\">Donald McFarlane<\/span><\/a><\/p>\n<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A group of Chinese-speaking cybercriminals is using artificial intelligence to orchestrate malicious attacks on government, media, technology, and gaming organizations, a research report has found.Dubbed UAT-10147, the group is among an emerging class of financially motivated intrusion operators using AI systems to operationalize offensive tradecraft at scale, Cisco Talos threat intelligence group researchers said.Talos threat intelligence researcher Joey Chenexplained in an August 20 blog postt<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26173","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26173"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26173\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26173"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}