logo

UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware

ID: 4648a71f-d4ae-5f5b-964c-67d4d03752a9

STIX ID: report--4648a71f-d4ae-5f5b-964c-67d4d03752a9

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2025-05-22

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

Cisco Talos documents active exploitation of CVE-2025-0994 against Cityworks servers by a Chinese-speaking actor (UAT-6382), detailing initial reconnaissance, rapid deployment of AntSword/Chopper web shells, Rust-based TetraLoader loaders (built with MaLoader) used to inject Cobalt Strike beacons and VShell implants, and providing extensive IOCs (file hashes, domains, IPs) and detection/mitigation guidance for affected U.S. local government networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.