Chinese-speaking hackers have exploited a now-patched Trimble Cityworks zero-day to breach multiple local governing bodies across the United States. Trimble Cityworks is a Geographic Information System (GIS)-based asset management and work order management software primarily used by local governments, utilities, and public works organizations and designed to help infrastructure agencies and municipalities manage public assets, handle permitting and licensing, and process work orders. The hacking group (UAT-6382) behind this campaign used a Rust-based malware loader to deploy Cobalt Strike beacons and VSHell malware designed to backdoor compromised systems and provide long-term persistent access, as well as web shells and custom malicious tools written in Chinese. These attacks started in January 2025, when Cisco Talos observed the first signs of reconnaissance activity within the breached organizations' networks. "Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to utilities management," said Cisco Talos security researchers Asheer Malhotra and Brandon White. "The web shells, including AntSword, chinatso/Chopper and generic file uploaders, contained messaging written in the Chinese language. Furthermore, the custom tooling, TetraLoader, was built using a malware-build...
Chinese hackers breach US local governments using Cityworks zero-day
BleepingComputer
·Sergiu Gatlan
·Published May 22, 2025
·Updated
Affected Software
3 affected components
Trimble Cityworks
Microsoft Internet Information Services (IIS)
Trimble Cityworks
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a breach of US local governments by Chinese hackers using a zero-day vulnerability in Trimble Cityworks.
2
What security implications are discussed in the article?
The article highlights concerns about the exploitation of zero-day vulnerabilities to infiltrate government systems and the risks posed by undetected cyber threats.
3
What products or software are affected?
The affected software includes Trimble Cityworks and Microsoft Internet Information Services (IIS).
4
Who are the perpetrators behind the cyber breach?
The breach is attributed to Chinese-speaking hackers targeting local governments in the United States.
5
What preventive measures were taken after the breach was discovered?
The exploited vulnerability in Trimble Cityworks has been patched to prevent further exploitation.