Cisco Researchers Found AI Hacking Tools Installed on a Criminal Group's Own Servers

Cisco Talos said in a report published Aug. 20 that a criminal group it tracks as UAT-10147 has been using AI tools as part of its break-ins of internet-facing web servers.
Talos says it found the PentestGPT framework installed on the group's command-and-control server and used to scan web servers and run ready-made exploits. It says it also recovered AI-generated operational playbooks, exploit automation scripts and troubleshooting logic that supported real intrusions. A second AI tool, DeepAudit, which scans source code for vulnerabilities, was found on the group's management server, but Talos writes that it has not observed the group exploiting anything DeepAudit found and assesses that it intends to use the tool that way.
An open directory on one of the group's servers contained a target list of roughly 170,000 URLs, which the operators had split into 17 files of about 10,000 each. Affected servers were located in Brazil, Bolivia, China, Canada and Vietnam across government, universities, media, technology and gaming organizations.
The group gained access through publicly disclosed vulnerabilities in widely used server software, essentially exploiting unlocked digital backdoors in platforms like Zimbra Collaboration Suite, AjaxPro and Telerik UI. Once inside, the group installed malware used for search-engine-optimization fraud and data theft.
UAT-10147 is a Chinese-speaking cybercrime group discovered in early 2026 with no attributed government ties. Cisco Talos assesses "with moderate-to-high confidence" that the group is "among an emerging class of financially motivated intrusion operators leveraging agentic AI systems to operationalize offensive tradecraft at scale." The observed activity indicates "a transition from AI-assisted scripting toward semi-autonomous offensive orchestration," although it is not the first of its kind.
