
Cybersecurity researchers have identified a threat actor that leverages artificial intelligence throughout the attack lifecycle to conduct search engine optimization (SEO) fraud, steal data, and maintain persistence in compromised environments.
What is the threat?
The threat actor, UAT-10147, uses a multi-platform toolkit that targets public-facing web servers. The toolkit combines capabilities such as command and control (C2), process injection, and credential theft with advanced evasion techniques and anti-analysis protections. As a result, the malware can bypass endpoint detection and response (EDR) solutions by adapting to security controls in real time.
Why is it noteworthy?
This toolkit supports a wide range of attack techniques rather than focusing on a single phase of an intrusion. Its broad functionality highlights a shift toward semi-autonomous attack operations.
The toolkit is also cross-platform and uses operating system-specific vulnerabilities, evasion techniques, and implants. This demonstrates the growing presence of agentic malware in the wild and reinforces the importance of timely patch management across both Windows and Linux systems.
What is the exposure or risk?
UAT-10147 has been observed targeting internet-exposed servers across multiple industries. Initial access is typically gained through remote code execution (RCE) vulnerabilities or existing implants.
Once access is established, the threat actor commonly deploys SEO malware and steals data. In some cases, the attacker may also install a web shell to enable future access or support additional malware deployment.
The following vulnerabilities have been linked to this activity:
- CVE-2022-27925 (Zimbra)
- CVE-2021-23758 (AjaxPro)
- CVE-2019-18935 (Telerik UI for ASP.NET AJAX)
- CVE-2021-29441 (Alibaba Nacos)
- CVE-2021-29442 (Alibaba Nacos)
What are the recommendations?
Barracuda recommends the following actions to reduce the likelihood and impact of an attack:
- Centralize logs in a SIEM for better visibility and monitoring.
- Regularly patch systems and audit exposed services.
- Isolate internet-facing devices and allow only necessary network traffic.
References
For more in-depth information about the recommendations, please visit the following links:
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.
This post originally appeared on Smarter MSP.

