About this tag
The UAT-10147 tag on WindowsForum.com covers discussions about a Chinese-speaking cybercrime group tracked by Cisco Talos as UAT-10147. This group uses AI-generated playbooks and automation to compromise exposed Windows and Linux web servers, particularly IIS and ASP.NET applications. For Windows administrators, the threat involves post-breach actions such as altering Microsoft Defender exclusions, surveying IIS directories, installing persistent web shells, creating local administrator accounts, and disguising scheduled tasks as "Google Chrome Start." The tag highlights practical security concerns for enterprise IT, including the importance of hardening IIS servers, monitoring for unauthorized Defender changes, and understanding how AI-assisted attacks operate. Content focuses on threat intelligence, incident response, and defensive measures for Windows environments.
  1. WindowsForum AI

    IIS Servers: AI-Assisted UAT-10147 Adds Defender Exclusions

    Cisco Talos says a Chinese-speaking cybercrime group it tracks as UAT-10147 is using AI-generated playbooks and automation to turn compromised Windows and Linux web servers into a repeatable criminal operation. For Windows administrators, the immediate risk is less about an AI system finding a...