Cobalt Strike and VShell were delivered by a Chinese-speaking threat actor known as UAT-6382, who took advantage of a now-patched remote-code-execution vulnerability in Trimble Cityworks.
In an investigation released today, Cisco Talos researchers Asheer Malhotra and Brandon White said that UAT-6382 effectively exploited CVE-2025-0944, carried out reconnaissance, and quickly installed a range of web shells and specially designed malware to sustain long-term access. After being granted access, UAT-6382 made it apparent that they wanted to switch to utility management systems.
According to the network security firm, beginning in January 2025, it saw attacks on the enterprise networks of local government entities in the US.
The deserialization of untrusted data vulnerability that affects GIS-centric asset management software and has the potential to allow remote code execution read more about Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
