A Chinese state-linked threat group, identified as UAT-6382, has exploited a previously patched vulnerability in Trimble Cityworks software to compromise local government networks in the United States, according to a report by Cisco Talos. The flaw, tracked as CVE-2025-0994 and carrying a CVSS v4 score of 8.6, is a deserialization vulnerability that can be exploited for remote code execution.
Despite being patched, the vulnerability was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog in February 2025. Since January, UAT-6382 has been leveraging this flaw to breach municipal systems, deploying Chinese-language web shells and custom malware with a focus on utility networks.
After gaining initial access, the attackers moved quickly to deploy web shells such as AntSword, Chopper (chinatso), and Behinder on IIS web servers. These were used to maintain access, conduct system reconnaissance, list directories, and identify active processes. The attackers then staged sensitive files for exfiltration and used PowerShell to implant backdoors across the compromised environment.
One of the notable tools employed by UAT-6382 is a Rust-based malware loader known as TetraLoader. Built using a malware development framework called MaLoader (written in Simplified Chinese), TetraLoader wraps malicious payloads in Rust binaries and injects them into legitimate processes like notepad.exe. These payloads include Cobalt Strike beacons and VShell stagers, providing the attackers with persistent remote access.
Cobalt Strike communications were observed connecting via HTTPS to domains such as cdn[.]lgaircon[.]xyz and www[.]roomako[.]com using stealthy, shellcode-injected configurations. Meanwhile, VShell stagers used hardcoded IP addresses and XOR encryption to deliver Go-based implants capable of full remote access functionality.
The infrastructure, tools, and malware used—many bearing Chinese-language messages and configurations—strongly indicate that UAT-6382 is a Chinese-speaking threat actor. The group’s consistent use of Chinese-written tools and command-and-control (C2) panels further reinforces this attribution.
Cisco Talos has released indicators of compromise (IOCs) to help organizations detect and defend against similar intrusions. The report underscores the ongoing threat posed by advanced persistent threats (APTs) targeting critical infrastructure through known software vulnerabilities.














Comments