Chinese hackers breach US local governments using Cityworks zero-day
ID: d124bd5b-93a9-552a-83a0-2afdffa7ecd7
STIX ID: report--d124bd5b-93a9-552a-83a0-2afdffa7ecd7
Feed Name: Bleeping Computer
Threat Score
Chinese-speaking threat group UAT-6382 exploited a now-patched Trimble Cityworks deserialization vulnerability (CVE-2025-0994) beginning in January 2025 to compromise multiple U.S. local government networks, deploying a Rust-based loader (TetraLoader), Cobalt Strike beacons, VSHell backdoors, web shells, and other custom tools; Trimble and CISA issued advisories and urged immediate patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
