Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

Posted on May 22, 2025May 22, 2025 By CWS

Could 22, 2025Ravie LakshmananVulnerability / Risk Intelligence
A Chinese language-speaking risk actor tracked as UAT-6382 has been linked to the exploitation of a now-patched remote-code-execution vulnerability in Trimble Cityworks to ship Cobalt Strike and VShell.
“UAT-6382 efficiently exploited CVE-2025-0944, carried out reconnaissance, and quickly deployed a wide range of internet shells and custom-made malware to keep up long-term entry,” Cisco Talos researchers Asheer Malhotra and Brandon White stated in an evaluation revealed at present. “Upon gaining entry, UAT-6382 expressed a transparent curiosity in pivoting to programs associated to utility administration.”
The community safety firm stated it noticed the assaults concentrating on enterprise networks of native governing our bodies in the US beginning January 2025.
CVE-2025-0944 (CVSS rating: 8.6) refers back to the deserialization of untrusted knowledge vulnerability affecting the GIS-centric asset administration software program that might allow distant code execution. The vulnerability, since patched, was added to the Recognized Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Safety Company (CISA) in February 2025.

Based on indicators of compromise (IoCs) launched by Trimble, the vulnerability has been exploited to ship a Rust-based loader that launches Cobalt Strike and a Go-based distant entry device named VShell in an try to keep up long-term entry to contaminated programs.
Cisco Talos, which is monitoring the Rust-based loader as TetraLoader, stated it is constructed utilizing MaLoader, a publicly accessible malware-building framework written in Simplified Chinese language.

Profitable exploitation of the susceptible Cityworks software ends in the risk actors conducting preliminary reconnaissance to establish and fingerprint the server, after which dropping internet shells like AntSword, chinatso/Chopper, and Behinder which are broadly put to make use of by Chinese language hacking teams.
“UAT-6382 enumerated a number of directories on servers of curiosity to establish recordsdata of curiosity to them after which staged them in directories the place they’d deployed internet shells for straightforward exfiltration,” the researchers stated. “UAT-6382 downloaded and deployed a number of backdoors on compromised programs through PowerShell.”

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.

The Hacker News Tags:Chinese, Cityworks, Exploit, Flaw, Government, Hackers, Infiltrate, Networks, Trimble, U.S

Post navigation

Previous Post: Cisco Webex Meetings Vulnerability Let Attackers Manipulate HTTP Responses
Next Post: Netwrix Password Manager Vulnerability Allows Authenticated Remote Code Execution

Related Posts

New TETRA Radio Encryption Flaws Expose Law Enforcement Communications New TETRA Radio Encryption Flaws Expose Law Enforcement Communications The Hacker News
Attackers Use Fake OAuth Apps with Tycoon Kit to Breach Microsoft 365 Accounts Attackers Use Fake OAuth Apps with Tycoon Kit to Breach Microsoft 365 Accounts The Hacker News
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools The Hacker News
Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News