INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Chinese-speaking adversary integrates agentic AI into post-compromise operations toolkit
| 2026-08-31 02:23 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS
Executive Summary
AI-generated
A new AI-built toolkit, referred to as "Gryxa," has been identified by ReliaQuest, which is highly likely used by a financially motivated threat actor for initial-access operations. The toolkit was developed with the help of an AI coding agent and is associated with several affected servers located in Brazil, Bolivia, China, Canada, and Vietnam. Gryxa integrates various tactics, including domain impersonation, subdomain impersonation, and exploitation of vulnerabilities, to automate intrusion operations and establish persistence. The current status indicates that the attack chain and post-compromise tactics used by UAT-10147, a Chinese-speaking cybercrime group tracked as the actor behind Gryxa, are still being assessed with moderate-to-high confidence.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2022-0995, CVE-2015-5287 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
py•••••.tool
wi•••••.com
gr•••••.com
ha•••••.md
us•••••.txt
ys•••••.exe
ch•••••.py
sv•••••.exe
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-0995CVE-2022-0995
CVE-2015-5287CVE-2015-5287
CVE-2010-3904CVE-2010-3904
CVE-2015-3246CVE-2015-3246
CVE-2022-27925CVE-2022-27925
CVE-2019-18935CVE-2019-18935
CVE-2021-29442CVE-2021-29442
CVE-2021-29441CVE-2021-29441
CVE-2022-0847CVE-2022-0847
CVE-2021-3156CVE-2021-3156
CVE-2021-23758CVE-2021-23758
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
governmentgovernment
mediamedia
technologytechnology
Incident Timeline
2026/08/31
The threat actor used a multi-stage malware deployment script that utilized certutil to download the achieved BadIIS (“dll.zip”) and a third execution script (“user.bat”) from a remote server, leveraging vulnerabilities in ABRT (Automatic Bug Reporting Tool) and Linux kernel's Reliable Datagram Sockets protocol implementation.
Click on any entity below to view its context and source!
organisation
IOC - Gryxa
IOC - Gryxa: The AI-Built Toolkit That Watches How You Remove It.
organisation
ReliaQuest
ReliaQuest has identified a new toolkit, referred to in its related public code repository as “Gryxa.”
infrastructure
Windows
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors.
…y perform the following activities:
The threat actor utilizes a privilege escalation tool to add standard IIS directories (“System32\inetsrv” and “SysWOW64\inetsrv”) to the Windows Defender exclusion list via PowerShell and Registry modifications.
Windows platform infection chain
Figure 4.
Windows infection chain.
The attack uses multiple Windows batch scripts to carry out its objectives.
Using the
EfsPotato
tool to gain elevated system privileges, the script modifies the Windows Registry and uses PowerShell to add specific directories to the Windows Defender exclusion list, effectively hiding the malware from antivirus scans.
prcc1.rar cmd.exe /C powershell Add-MpPreference -ExclusionPath C:\Windows\SysWOW64\inetsrv
prcc1.rar
cmd.exe /C powershell Add-MpPreference -ExclusionPath C:\Windows\System32\inetsrv
prcc1.rar cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Windows\SysWOW64\inetsrv" /t
REG_DWORD /d 0 /f
prcc1.rar cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Windows\System32\inetsrv" /t
prcc1.rar cmd.exe /C C:\Windows\system32\inetsrv\appcmd list site /config /xml
Known one-day vulnerabilities
The threat actor heavily relies on publicly disclosed vulnerabilities to achieve RCE across both Windows and Linux web servers.
Upon class loading, the payload invokes
Runtime.exec()
to spawn an OS-level shell, dynamically adapting to the victim's environment by executing /bin/bash on Linux or falling back to cmd.exe on Windows.
It POSTs the output of id and hostname (on Linux) or
%USERNAME%
and
%COMPUTERNAME%
(on Windows) directly to an attacker-controlled Nacos configuration server.
Confirm baseline write capability (“c:\windows\temp”) that validates RCE is functional
Exfiltrate the ACL of the target webroot (icacls) that checks if IUSR/IIS_IUSRS can write
Attempt direct file write to the webroot, capturing the exact excepti…
infrastructure
Linux
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors.
Known one-day vulnerabilities
The threat actor heavily relies on publicly disclosed vulnerabilities to achieve RCE across both Windows and Linux web servers.
Upon class loading, the payload invokes
Runtime.exec()
to spawn an OS-level shell, dynamically adapting to the victim's environment by executing /bin/bash on Linux or falling back to cmd.exe on Windows.
It POSTs the output of id and hostname (on Linux) or
%USERNAME%
and
%COMPUTERNAME%
(on Windows) directly to an attacker-controlled Nacos configuration server.
CVE-2022-0995
targets a flaw in the Linux kernel's watch_queue event notification mechanism, allowing an unprivileged user to write arbitrary data out-of-bounds and achieve privilege escalation.
CVE-2022-0847
, widely known as "Dirty Pipe," is a high-severity Linux kernel vulnerability that allows unprivileged users to overwrite data in read-only files by exploiting a flaw in the way pipe buffers are handled, effectively enabling privilege…
Linux platform infection chain
Figure 8.
Linux infection chain.
Following successful exploitation, a web shell is deployed on the compromised Linux server, providing the attacker with persistent and interactive command execution capabilities.
CVE-2010-3904
, one of the older vulnerabilities in the chain, exploits a flaw in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation, specifically in the rds_page_copy_user function, allowing a local unprivileged user to wri…
The threat actor successfully exploited a website and gathered information about the victim machine using Linux commands.
data_breach
17 files
To improve performance, they split the large list into 17 files, each containing about 10,000 URLs.
data_breach
100 bytes
The final step confirms that the web shell is live by fetching it and verifying that the HTTP response size exceeds 100 bytes.
financial
2 Win
Py.Loader.Tool-10060293-1
Py.Loader.Tool-10060293-2
Win.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors.
…y perform the following activities:
The threat actor utilizes a privilege escalation tool to add standard IIS directories (“System32\inetsrv” and “SysWOW64\inetsrv”) to the Windows Defender exclusion list via PowerShell and Registry modifications.
Windows platform infection chain
Figure 4.
Windows infection chain.
The attack uses multiple Windows batch scripts to carry out its objectives.
Using the
EfsPotato
tool to gain elevated system privileges, the script modifies the Windows Registry and uses PowerShell to add specific directories to the Windows Defender exclusion list, effectively hiding the malware from antivirus scans.
prcc1.rar cmd.exe /C powershell Add-MpPreference -ExclusionPath C:\Windows\SysWOW64\inetsrv
prcc1.rar
cmd.exe /C powershell Add-MpPreference -ExclusionPath C:\Windows\System32\inetsrv
prcc1.rar cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Windows\SysWOW64\inetsrv" /t
REG_DWORD /d 0 /f
prcc1.rar cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Windows\System32\inetsrv" /t
prcc1.rar cmd.exe /C C:\Windows\system32\inetsrv\appcmd list site /config /xml
Known one-day vulnerabilities
The threat actor heavily relies on publicly disclosed vulnerabilities to achieve RCE across both Windows and Linux web servers.
Upon class loading, the payload invokes
Runtime.exec()
to spawn an OS-level shell, dynamically adapting to the victim's environment by executing /bin/bash on Linux or falling back to cmd.exe on Windows.
It POSTs the output of id and hostname (on Linux) or
%USERNAME%
and
%COMPUTERNAME%
(on Windows) directly to an attacker-controlled Nacos configuration server.
Confirm baseline write capability (“c:\windows\temp”) that validates RCE is functional
Exfiltrate the ACL of the target webroot (icacls) that checks if IUSR/IIS_IUSRS can write
Attempt direct file write to the webroot, capturing the exact excepti…
Metrics
infrastructure
Linux
Affected Product
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors.
CVE-2022-0995
targets a flaw in the Linux kernel's watch_queue event notification mechanism, allowing an unprivileged user to write arbitrary data out-of-bounds and achieve privilege escalation.
CVE-2022-0847
, widely known as "Dirty Pipe," is a high-severity Linux kernel vulnerability that allows unprivileged users to overwrite data in read-only files by exploiting a flaw in the way pipe buffers are handled, effectively enabling privilege…
Linux platform infection chain
Figure 8.
Linux infection chain.
Following successful exploitation, a web shell is deployed on the compromised Linux server, providing the attacker with persistent and interactive command execution capabilities.
CVE-2010-3904
, one of the older vulnerabilities in the chain, exploits a flaw in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation, specifically in the rds_page_copy_user function, allowing a local unprivileged user to wri…
Known one-day vulnerabilities
The threat actor heavily relies on publicly disclosed vulnerabilities to achieve RCE across both Windows and Linux web servers.
Upon class loading, the payload invokes
Runtime.exec()
to spawn an OS-level shell, dynamically adapting to the victim's environment by executing /bin/bash on Linux or falling back to cmd.exe on Windows.
It POSTs the output of id and hostname (on Linux) or
%USERNAME%
and
%COMPUTERNAME%
(on Windows) directly to an attacker-controlled Nacos configuration server.
The threat actor successfully exploited a website and gathered information about the victim machine using Linux commands.
Metrics
data_breach
17
Files
To improve performance, they split the large list into 17 files, each containing about 10,000 URLs.
Metrics
data_breach
100
Bytes
The final step confirms that the web shell is live by fetching it and verifying that the HTTP response size exceeds 100 bytes.
Metrics
financial
2
Win
Py.Loader.Tool-10060293-1
Py.Loader.Tool-10060293-2
Win.
Intelligence Sources
Talos Intelligence
2026-08-20
AlienVault OTX
2026-08-31
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:16
Comprehensive Tactical Telemetry
Highly Correlated Entities
43x
organisation
Identified Entity
IOC - Gryxa
entity
11x
vulnerability
Exploited CVE
CVE-2022-0995
cve
8x
general metric
Section
6
section
6x
tactic
Cyber Operation Type
Impersonation
tactic
5x
industry
Targeted Sector
Defense
sector
5x
target region
Target Country
Brazil
country
5x
tactic
MITRE ATT&CK Technique
T1059.001 - PowerShell
technique
3x
general metric
Entities
11
entities
2x
infrastructure
Affected Product
Windows
software
2x
timeline
Temporal Reference
early 2026
date
Contextual Telemetry
Context Block
14 METRICS
malware
Offensive Tool
Metasploit
tool
general metric
Cve-2022
995
cve-2022
general metric
/D
0
/d
general metric
Http Callbacks
12
http callbacks
general metric
Site Directories
13
site directories
general metric
萬
10,000
萬
general metric
Urls
170,000
urls
general metric
Distinct Error Messages
500
distinct error messages
general metric
-
1
-
data breach
Files
17
files
general metric
Digits].[7
10
digits].[7
general metric
.Net
5
.net
data breach
Bytes
100
bytes
financial
Win
2
win
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.