INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Chinese-speaking adversary integrates agentic AI into post-compromise operations toolkit

| 2026-08-31 02:23 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS
Executive Summary
AI-generated
A new AI-built toolkit, referred to as "Gryxa," has been identified by ReliaQuest, which is highly likely used by a financially motivated threat actor for initial-access operations. The toolkit was developed with the help of an AI coding agent and is associated with several affected servers located in Brazil, Bolivia, China, Canada, and Vietnam. Gryxa integrates various tactics, including domain impersonation, subdomain impersonation, and exploitation of vulnerabilities, to automate intrusion operations and establish persistence. The current status indicates that the attack chain and post-compromise tactics used by UAT-10147, a Chinese-speaking cybercrime group tracked as the actor behind Gryxa, are still being assessed with moderate-to-high confidence.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2022-0995, CVE-2015-5287 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in- • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

py•••••.tool
wi•••••.com
gr•••••.com
ha•••••.md
us•••••.txt
ys•••••.exe
ch•••••.py
sv•••••.exe
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-0995CVE-2022-0995 CVE-2015-5287CVE-2015-5287 CVE-2010-3904CVE-2010-3904 CVE-2015-3246CVE-2015-3246 CVE-2022-27925CVE-2022-27925 CVE-2019-18935CVE-2019-18935 CVE-2021-29442CVE-2021-29442 CVE-2021-29441CVE-2021-29441 CVE-2022-0847CVE-2022-0847 CVE-2021-3156CVE-2021-3156 CVE-2021-23758CVE-2021-23758
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation governmentgovernment mediamedia technologytechnology
Incident Timeline
‎2026/08/31
The threat actor used a multi-stage malware deployment script that utilized certutil to download the achieved BadIIS (“dll.zip”) and a third execution script (“user.bat”) from a remote server, leveraging vulnerabilities in ABRT (Automatic Bug Reporting Tool) and Linux kernel's Reliable Datagram Sockets protocol implementation.
organisation IOC - Gryxa
organisation ReliaQuest
infrastructure Windows
infrastructure Linux
data_breach 17 files
data_breach 100 bytes
financial 2 Win
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
data_breach
17
Files
Metrics
data_breach
100
Bytes
Metrics
financial
2
Win
Intelligence Sources