US local governments targeted by Chinese hackers


- Multiple US government agencies were targeted by Chinese hackers, Cisco Talos warns
- The hackers used a bug in Trimble Cityworks
- The vulnerability was fixed in February this year
Local government organizations across the United States were recently targeted by a Chinese threat actor looking to deploy various web shells and malware loaders. This is according to cybersecurity researchers Cisco Talos, who have been tracking the attacks since early 2025.
Cisco says the threat actors are tracked as UAT-6382 (usually short for Unknown Adversary Threat), and have been targeting organizations through a zero-day vulnerability in Trimble Cityworks.
Trimble Cityworks is a Geographic Information System (GIS) asset management and permitting software designed to help local governments and utilities manage infrastructure, maintenance, and operations efficiently.
In February this year, we reported the software was vulnerable to CVE-2025-0994, a high-severity deserialization bug with a severity score of 8.6 (high). The vulnerability allowed threat actors to perform remote code execution (RCE).
Cisco said the attackers used the zero-day to drop a Rust-based malware loader which, in turn, installed Cobalt Strike beacons and VSHell malware, which provided the Chinese with long-term, persistent access.
Patching the flaw
“Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to utilities management,” Cisco said in its security advisory.
With access established, the attackers started dropping different web shells: AntSword, chinatso/Chopper, and more. All of these are written in Chinese. They were also dropping a custom loader called TetraLoader, which was written in Simplified Chinese.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
As soon as news of the zero-day broke, Trimble released a patch, bringing Cityworks to versions 15.8.9 and 23.10 and mitigating the risk. It also warned about discovering some on-prem deployments having overprivileged IIS identity permissions, and added that some deployments haid incorrect attachment directory configurations.
At the time, there were no reports of victims or damages, but the US Cybersecurity and Infrastructure Agency (CISA) still released a coordinated advisory, urging customers to apply the patches as soon as possible. In early February, the agency added it to KEV, giving Federal Civilian Executive Branch agencies a deadline to patch.
Via BleepingComputer
You might also like
Multiple US government agencies were targeted by Chinese hackers, Cisco Talos warns The hackers used a bug in Trimble Cityworks The vulnerability was fixed in February this year Local government organizations across the United States were recently targeted by a Chinese threat actor looking to deploy various web shells and…
Recent Posts
Archives
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010