logo

Chinese hackers breach US local governments using Cityworks zero-day

ID: d124bd5b-93a9-552a-83a0-2afdffa7ecd7

STIX ID: report--d124bd5b-93a9-552a-83a0-2afdffa7ecd7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Chinese-speaking threat group UAT-6382 exploited a now-patched Trimble Cityworks deserialization vulnerability (CVE-2025-0994) beginning in January 2025 to compromise multiple U.S. local government networks, deploying a Rust-based loader (TetraLoader), Cobalt Strike beacons, VSHell backdoors, web shells, and other custom tools; Trimble and CISA issued advisories and urged immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.