UAT-6382 is a Chinese-speaking threat activity cluster associated with intrusions into United States local government enterprise networks beginning in January 2025. It exploited CVE-2025-0994, a remote code execution vulnerability in Trimble Cityworks, as a zero-day to gain initial access. Its operators conducted rapid reconnaissance, enumerated directories and running processes, staged backup archives for exfiltration, and attempted to pivot toward utilities-management systems. Chinese-language tooling and hands-on-keyboard behavior support the characterization of its operators as Chinese-speaking, but do not establish their country of origin or state sponsorship. UAT-6382 deployed AntSword, Chopper/chinatso, Behinder, and generic file-upload web shells on compromised IIS servers to support continued access and additional payload deployment. It used TetraLoader, a Rust-based loader built with the Chinese-language MaLoader framework, to decode or decrypt embedded payloads and inject them into benign processes. Observed payloads included Cobalt Strike beacons and the SNOWLIGHT stager for VShell. The VShell implant provides remote command execution, file management, screenshot capture, and proxying capabilities. SNOWLIGHT is also used by other threat clusters, including UNC5174, UNC6586, and UAT-8302; shared tooling does not establish that these clusters are aliases of UAT-6382.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The attackers have been leveraging a Cityworks RCE vulnerability (CVE-2025-0994) to get access to the targeted environments and perform the initial reconnaissance.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Threat cluster observed exploiting a Cityworks zero-day to deploy VSHELL using the SNOWLIGHT stager.
Chinese-speaking intrusion cluster exploiting Trimble Cityworks CVE-2025-0944 to deploy web shells/custom malware and post-exploitation tooling (Cobalt Strike, VShell) for long-term access.
UAT-6382 exploits a Cityworks remote code execution vulnerability to compromise environments and conduct initial reconnaissance. The attackers deploy web shells and backdoors, including the Rust-based TetraLoader, which is based on the MaLoader malware creation framework and delivers additional payloads such as Cobalt Strike and a VShell stager.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.