Chinese-speaking threat actors have successfully breached multiple local government networks across the United States by exploiting a critical vulnerability in Trimble Cityworks, a GIS-based asset management system widely used by municipalities and utilities.
## The Attack Campaign
Security researchers from Cisco Talos identified a hacking group, designated UAT-6382, that began targeting US local governing bodies in January 2025. After gaining initial access, the attackers showed particular interest in systems related to utilities management.
“Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to utilities management,” reported Cisco Talos researchers Asheer Malhotra and Brandon White.
## Attack Methods and Tools
The hackers leveraged CVE-2025-0994, a high-severity deserialization vulnerability in Trimble Cityworks that allows authenticated attackers to execute remote code on Microsoft IIS servers. Their arsenal included:
– A Rust-based malware loader called TetraLoader
– Cobalt Strike beacons for command and control
– VSHell backdoor malware for persistent access
– Various web shells including AntSword and Chopper
– Custom malicious tools with Chinese-language components
Evidence of Chinese origin includes web shells containing Chinese-language messaging and the use of “MaLoader,” a malware-builder written in Simplified Chinese.
## Federal Response
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-0994 to its catalog of actively exploited vulnerabilities on February 7, mandating federal agencies patch their systems within three weeks under Binding Operational Directive 22-01.
On February 11, CISA expanded its warning to organizations in critical infrastructure sectors including water systems, energy, transportation, government facilities, and communications, urging them to “install the updated version immediately.”
Trimble acknowledged in early February that attackers were actively exploiting the vulnerability and released security updates to patch the flaw.
