A Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity points to increasingly automated offensive operations.Talos, which tracks the group as UAT-10147, found evidence that AI-generated operational guidance had been used during an intrusion. Researchers also recovered tooling that helped the attackers refine exploits when problems arose and automate parts of their activity after gaining access.The campaign relied heavily on publicly disclosed vulnerabilities, Talos said. The use of AI could nevertheless allow attackers to carry out complex operations more efficiently while requiring less specialist expertise.Researchers also found a target list containing about 170,000 URLs on the group’s command-and-control infrastructure, illustrating the breadth of the group’s potential targets.Talos said UAT-10147 is financially motivated and has used compromised servers for activities including data theft and search-engine optimization fraud.AI shortens the defender’s response windowUAT-10147 represents a shift in attacker capability even though the underlying techniques are not new, according to Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services.“What has changed is how quickly AI can help attackers troubleshoot failed exploits, adapt payloads, and move from initial access to persistence,” Grover said.Keith Prabhu, founder and CEO of Confidis, described the change as incremental but meaningful rather than a wholesale shift in attack techniques.He said AI can compress the time between initial access and a reliable, repeatable compromise by allowing attackers to work through vulnerable internet-facing systems with an automated feedback loop.“CISOs will have to work at the speed of the attack and not the speed of their current capabilities,” Prabhu said.That could make smaller organizations more attractive targets if compromising them requires less manual effort. “For CISOs, the key takeaway is that the window to detect and contain an intrusion is getting much shorter,” Grover said.That shrinking response window could expose weaknesses in incident-response processes that still depend on several layers of human approval.Prabhu said SOCs may also struggle if they continue to investigate alerts individually rather than correlating activity across an intrusion. Heavy reliance on signature-based detection and slow manual triage could create further delays, while poor server telemetry may leave defenders without sufficient visibility into an intrusion.Grover warned that if attackers can establish persistence within minutes, security teams may not have time to wait for multiple teams or managers to approve isolation of a compromised system.Organizations therefore need pre-approved containment actions for high-confidence incidents, with clear governance around when automated defenses are allowed to act, Grover said. She pointed to an IDC forecast that 75% of organizations will automate SOC triage by 2028 as companies seek to reduce alert fatigue and accelerate response.Defenders turn to automationThe growing use of automation by attackers is increasing pressure on organizations to expand their own use of AI-driven defenses, according to Jonathan Ong, senior analyst for managed security services at Omdia.“The question is no longer whether AI offensive tools will proliferate widely but whether defenders will be ready when they do,” Ong said. He added that human oversight will remain necessary even as organizations deploy more automated defenses.Ong pointed to managed detection and response services and external attack surface management, or EASM, as areas where greater automation could help defenders identify and respond to internet-facing risks.Known vulnerabilities become more urgentUAT-10147 also illustrates why AI-enabled attacks could make exposure more important than vulnerability severity alone. The group gained operational advantages from AI while relying heavily on known vulnerabilities and existing offensive tools.AI can automate much of the work involved in finding vulnerable servers and determining whether an exploit succeeded, Grover said, potentially increasing the speed at which attackers work through exposed systems.That makes CVSS scores alone an insufficient basis for prioritization. An internet-facing flaw with publicly available exploit code may warrant remediation before a higher-scoring vulnerability buried inside an internal network. Security teams should also consider what systems or privileged identities an attacker could reach after compromising the affected asset.Grover added that where immediate patching is not possible, compensating controls such as segmentation or temporary isolation may help reduce risk.“AI does not change the fundamentals of security,” Grover said. “It simply allows attackers to do so faster, more consistently, and at a much larger scale.”