• News/
  • https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-us-local-governments-using-cityworks-zero-day/

Chinese hackers breach US local governments using Cityworks zero-day

BleepingComputer
·
Sergiu Gatlan
·
Published May 22, 2025
·
Updated

Chinese-speaking hackers have exploited a now-patched Trimble Cityworks zero-day to breach multiple local governing bodies across the United States. Trimble Cityworks is a Geographic Information System (GIS)-based asset management and work order management software primarily used by local governments, utilities, and public works organizations and designed to help infrastructure agencies and municipalities manage public assets, handle permitting and licensing, and process work orders. The hacking group (UAT-6382) behind this campaign used a Rust-based malware loader to deploy Cobalt Strike beacons and VSHell malware designed to backdoor compromised systems and provide long-term persistent access, as well as web shells and custom malicious tools written in Chinese. These attacks started in January 2025, when Cisco Talos observed the first signs of reconnaissance activity within the breached organizations' networks. "Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to utilities management," said Cisco Talos security researchers Asheer Malhotra and Brandon White. "The web shells, including AntSword, chinatso/Chopper and generic file uploaders, contained messaging written in the Chinese language. Furthermore, the custom tooling, TetraLoader, was built using a malware-build...

Read full article

Affected Software

3 affected components
Trimble Cityworks
Microsoft Internet Information Services (IIS)
Trimble Cityworks
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a breach of US local governments by Chinese hackers using a zero-day vulnerability in Trimble Cityworks.

2

What security implications are discussed in the article?

The article highlights concerns about the exploitation of zero-day vulnerabilities to infiltrate government systems and the risks posed by undetected cyber threats.

3

What products or software are affected?

The affected software includes Trimble Cityworks and Microsoft Internet Information Services (IIS).

4

Who are the perpetrators behind the cyber breach?

The breach is attributed to Chinese-speaking hackers targeting local governments in the United States.

5

What preventive measures were taken after the breach was discovered?

The exploited vulnerability in Trimble Cityworks has been patched to prevent further exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203