UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware
ID: 4648a71f-d4ae-5f5b-964c-67d4d03752a9
STIX ID: report--4648a71f-d4ae-5f5b-964c-67d4d03752a9
Feed Name: Cisco Talos
Threat Score
Cisco Talos documents active exploitation of CVE-2025-0994 against Cityworks servers by a Chinese-speaking actor (UAT-6382), detailing initial reconnaissance, rapid deployment of AntSword/Chopper web shells, Rust-based TetraLoader loaders (built with MaLoader) used to inject Cobalt Strike beacons and VShell implants, and providing extensive IOCs (file hashes, domains, IPs) and detection/mitigation guidance for affected U.S. local government networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
