Chinese threat actors exploited Trimble Cityworks Flaw to breach U.S. local government networks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0944 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file customerview.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2025-0994 | Authenticated Deserialization RCE in Trimble Cityworks Trimble Cityworks, a GIS-based asset management platform used largely by local governments and utilities, contains a deserialization vulnerability (CWE-502). An authenticated user triggers the flaw by submitting maliciously crafted serialized input to the Cityworks web application. Successful exploitation yields remote code execution on the underlying Microsoft IIS web server hosting the product. Any organization running Cityworks on IIS is affected, especially where the server is internet-facing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-07, confirming exploitation in the wild; no public PoC is known, CVSS scoring is pending, and EPSS assigns roughly a 31% probability of exploitation within 30 days. Do: Patch or apply Trimble's mitigations to all Cityworks/IIS servers per vendor instructions, as required by the CISA KEV listing, and discontinue use if mitigations are unavailable. Because exploitation requires authentication, review and rotate Cityworks accounts and credentials, and inspect IIS/application logs on exposed servers for signs of compromise (ransomware use is unconfirmed but possible). | 8.6 | 31% | KEV |
| nicheroughly hundreds to low thousands of deployments, concentrated at local governments, utilities and public agencies (estimate; no public install counts… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdn.lgaircon.xyz | alt Strike beacons used by UAT-6382 connect to domains like cdn[.]lgaircon[.]xyz and www[.]roomako[.]com via HTTPS, using stealthy confi |
| domain | www.roomako.com | y UAT-6382 connect to domains like cdn[.]lgaircon[.]xyz and www[.]roomako[.]com via HTTPS, using stealthy configs with injected shellco |
Full article393 words · extracted from securityaffairs.com · click to collapse

A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy Cobalt Strike and VShell.
Cisco Talos researchers attribute the exploitation of the CVE-2025-0994 in Trimble Cityworks to Chinese-speaking threat actor UAT-6382, based on tools and TTPs used in the intrusions.
The vulnerability CVE-2025-0994 (CVSS v4 score of 8.6) is a deserialization of untrusted data issue. An attacker could trigger the flaw to achieve remote code execution.
In February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Trimble Cityworks vulnerability to its Known Exploited Vulnerabilities catalog.
Since January 2025, UAT-6382 has exploited CVE-2025-0944 to breach U.S. local government networks, deploying Chinese-language web shells and custom malware to target utility systems.
“Post-compromise activity involves the rapid deployment of web shells such as AntSword and chinatso/Chopper on the underlying IIS web servers. UAT-6382 also employed the use of Rust-based loaders to deploy Cobalt Strike and VSHell malware to maintain long-term persistent access.” reads the report published by Talos. “We track the Rust-based loaders as “TetraLoader,” built using a recently publicly available malware building framework called “MaLoader.” MaLoader, written in Simplified Chinese, allows its operators to wrap shellcode and other payloads into a Rust-based binary, resulting in the creation of TetraLoader.”
Exploiting the Cityworks vulnerability, attackers ran commands for server reconnaissance, gathering system info, listing directories, and active tasks, before placing web shells in targeted folders.
UAT-6382 quickly deployed web shells like AntSword, chinatso, and Behinder, often with Chinese-language messages, to gain persistent access. They scanned directories, staged sensitive files for exfiltration, and used PowerShell to deploy multiple backdoors across compromised systems.
TetraLoader is a Rust-based malware loader that injects decoded payloads into benign processes like notepad.exe. It delivers Cobalt Strike beacons or VShell stagers to infected systems. The malware is built with MaLoader and written in Simplified Chinese, suggesting that they are linked to Chinese-speaking threat actors.
Cobalt Strike beacons used by UAT-6382 connect to domains like cdn[.]lgaircon[.]xyz and www[.]roomako[.]com via HTTPS, using stealthy configs with injected shellcode. VShell stagers connect to hardcoded IPs, receive XOR-encrypted payloads, and deploy Go-based implants supporting full RAT functions. Tools and C2 panels are Chinese-written, indicating Chinese-speaking operators.
Talos published the indicators of compromise (IOCs).
The IOCs can also be found in our GitHub repository here.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, China)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178203/hacking/chinese-threat-actors-exploited-trimble-cityworks-flaw-to-breach-u-s-local-government-networks.html