Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks
Cobalt Strike and VShell were delivered by a Chinese-speaking threat actor known as UAT-6382, who took advantage of a now-patched remote-code-execution vulnerability in Trimble Cityworks.
In an investigation released today, Cisco Talos researchers Asheer Malhotra and Brandon White said that UAT-6382 effectively exploited CVE-2025-0944, carried out reconnaissance, and quickly installed a range of web shells and specially designed malware to sustain long-term access. After being granted access, UAT-6382 made it apparent that they wanted to switch to utility management systems.
According to the network security firm, beginning in January 2025, it saw attacks on the enterprise networks of local government entities in the US.
The deserialization of untrusted data vulnerability that af...

