A threat actor identified as UAT-10147 is leveraging artificial intelligence throughout the attack lifecycle to conduct SEO fraud, steal data, and maintain persistence in compromised environments, according to a recent report by Smarter MSP.UAT-10147 employs a multi-platform toolkit targeting public-facing web servers, combining command and control, process injection, and credential theft with advanced evasion techniques. This allows the malware to bypass endpoint detection and response solutions by adapting in real time. The toolkit supports a wide range of attack techniques, indicating a move towards semi-autonomous operations. It is also cross-platform, utilizing OS-specific vulnerabilities and implants, highlighting the importance of timely patch management for both Windows and Linux systems.The threat actor has been observed targeting internet-exposed servers across various industries, typically gaining initial access through remote code execution vulnerabilities or existing implants. Once inside, UAT-10147 deploys SEO malware, steals data, and sometimes installs web shells for future access. Vulnerabilities linked to this activity include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).Source: Smarter MSP