Mark RadarMARK RADAR
About
EN
Sign in

China-Linked Hackers Use AI-Built Tools in Global Server Campaign

1 reports · First detected 2026-08-24 · Last active 2026-08-24

Cisco Talos has identified UAT-10147 as a China-linked hacking group targeting vulnerable servers worldwide. The campaign matters because artificial intelligence is being used across reconnaissance, exploitation and malware development, moving beyond basic coding assistance. Such integration can reduce the time and expertise needed to mount large-scale intrusions, while allowing attackers to scan infrastructure and adapt offensive tools more efficiently.

Talos said UAT-10147 assembled a list of more than 170,000 targets globally and focused on servers exposed to known vulnerabilities. The group incorporated AI-built tools into several stages of its operations, creating what researchers described as a semi-autonomous attack workflow. The findings indicate that threat actors are increasingly combining automation and generative AI to broaden targeting, accelerate exploitation and develop malicious software at greater scale.

All Coverage

1 original reports

The Backstory

The history behind this event
China-Linked Hackers Unleash Autonomous AI Attack on Taiwan2026-08-14 · 6 reports · similarity 0.82

Taiwan has long been a frontline target of Chinese cyber-espionage, with government agencies and critical infrastructure under sustained pressure. Israeli cybersecurity company Dream’s findings mark a potential step change: rather than merely helping human operators write code or analyze data, open-source AI agents allegedly mapped networks, selected vulnerabilities, attempted intrusions and changed tactics when blocked. The case matters because autonomous, parallel agents could let attackers operate faster and at far greater scale while lowering the expertise and cost needed for sophisticated campaigns.

Dream said on Aug. 12 that the suspected China-linked campaign ran for four days in early July, deploying as many as eight AI agents at once. The agents mapped 21 government systems, compromised at least 85 accounts and stole more than 2,500 personnel records, while also probing Taiwan’s nuclear safety agency and at least seven energy companies. Taiwan’s Administration for Cyber Security said on Aug. 13 that it had issued alerts beginning July 20 and helped affected agencies complete remediation, though the government did not publicly attribute the operation to China.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)