UAT-10147 uses agentic AI server exploitation to target media infrastructure
Cisco Talos has identified a threat actor, UAT-10147, utilizing agentic AI to automate reconnaissance, exploit validation, and payload generation against web servers. The group targets various sectors, including media and gaming, by integrating AI-driven tools like PentestGPT and DeepAudit into their offensive workflows.
Key Takeaways
- Threat actor UAT-10147 targeted a list of 170,000 URLs, splitting them into 10,000-unit batches for efficient scanning.
- The group uses PentestGPT to dynamically scan web servers and DeepAudit for automated source code vulnerability analysis.
- AI-generated Python scripts were recovered that automate the deployment of the SPECTRE implant and ASHX web shells.
- Attackers leveraged known vulnerabilities including CVE-2022-0847 (Dirty Pipe) and .NET deserialization flaws to gain root access.
- The campaign utilizes legitimate SaaS platforms like webhook.site to blend exfiltration traffic with normal administrative operations.
Why It Matters
The transition from AI-assisted scripting to semi-autonomous offensive orchestration allows lower-tier actors to execute complex, multi-stage intrusions against high-value media targets. By using agentic systems to troubleshoot exploits in real-time and generate operational playbooks, UAT-10147 significantly reduces the time between vulnerability discovery and full system compromise. For the streaming industry, this necessitates a shift toward defensive strategies that prioritize MachineKey confidentiality and out-of-band callback monitoring to detect silent successes in error streams. Watch for increased adoption of AI-driven defensive auditing tools by infrastructure providers to counter these automated reconnaissance workflows.
Additional Context
The emergence of UAT-10147 as an agentic AI-powered threat actor targeting media and gaming infrastructure reflects a broader acceleration in AI-driven offensive capabilities across the cybersecurity landscape. Cisco Talos researchers have documented how the group integrates tools like PentestGPT and DeepAudit into semi-autonomous attack chains, but the underlying trend extends beyond a single actor. Ericsson's networks chief Per Narvinger highlighted at MWC 2026 that AI-driven optimization in telecom networks can yield 10 percent more spectrum efficiency, demonstrating how the same AI capabilities being applied defensively in network operations are mirrored by offensive actors probing those same infrastructures. The convergence of AI in both network management and attack automation creates an asymmetric arms race that media infrastructure operators must now account for.
The business implications of agentic AI in network operations are becoming clearer as operators invest heavily in autonomous systems. Blue Planet and Telefónica Deutschland completed a joint proof of concept using agentic AI to power 5G network slicing services, demonstrating that tasks requiring specialized expertise could be completed in minutes instead of weeks. That same efficiency gain is precisely what makes agentic AI attractive to threat actors like UAT-10147, who can automate reconnaissance and exploit validation workflows that previously demanded significant manual expertise. ABI Research has forecast network slicing to become a $19.5 billion market by 2028, meaning the attack surface for AI-driven exploitation of media delivery infrastructure will expand substantially as operators deploy these services at scale.
Technical analysis of agentic AI architectures reveals why defensive postures must evolve. Ericsson published details on its agentic AI ecosystem for network optimization, describing a supervisor agent coordinating specialized agents that process over 60,000 KPIs to identify 20 distinct classes of network issues. This multi-agent coordination pattern mirrors the offensive workflows documented by Cisco Talos, where UAT-10147 chains reconnaissance, exploit validation, and payload generation into automated sequences. Ericsson's Mobility Report found that ChatGPT accounted for 60 percent of total AI traffic and 70 percent of all AI traffic in the uplink as of mid-2025, indicating that AI-generated traffic patterns are already reshaping network load profiles. For streaming infrastructure operators, distinguishing legitimate AI-driven traffic from automated reconnaissance probes targeting video delivery systems will require new detection heuristics that account for the behavioral signatures of .
Read full article at blog.talosintelligence.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source