Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

## Cybersecurity: Zero-Day Vulnerability in Cityworks

Cybersecurity: Zero-Day Vulnerability in Cityworks

Cisco Talos has identified active exploitation of a zero-day remote-code-execution vulnerability, CVE-2025-0994, in Cityworks, an asset management system. This vulnerability has been exploited by a group identified as UAT-6382, believed to be Chinese-speaking threat actors, targeting enterprise networks of local governing bodies in the United States since January 2025.

The attackers aim to infiltrate systems related to utilities management, deploying web shells and custom malware on Internet Information Services (IIS) web servers. Both the Cybersecurity and Infrastructure Security Agency (CISA) and Trimble, the vendor of Cityworks, have issued advisories. Trimble has provided specific indicators of compromise (IOCs) that align with Talos’s findings.

Upon successful exploitation of the vulnerability, UAT-6382 conducts reconnaissance using commands like ipconfig , dir , and tasklist . Web shells such as AntSword, chinatso/Chopper, and Behinder are then deployed, often containing Chinese-language messaging.

The threat actors utilize Rust-based loaders, named “TetraLoader,” which are built using a Simplified Chinese framework called “MaLoader.” These loaders inject malicious payloads, including Cobalt Strike beacons, into benign processes like notepad.exe .

Cisco Talos has identified active exploitation of a zero-day remote-code-execution vulnerability, CVE-2025-0994, in Cityworks, an asset management system.
Amanda Parks · Thehackingpost

VShell, a GoLang-based implant, is used to provide extensive remote access capabilities. The campaign focuses on critical infrastructure, using PowerShell commands to download additional backdoors from malicious IPs.

TetraLoader Hashes: 14ed3878b6623c287283a8a80020f68e1cb6bfc37b236f33a95f3a64c4f4611f, … Cobalt Strike Hashes: C02d50d0eb3974818091b8dd91a8bbb8cdefd94d4568a4aea8e1dcdd8869f738 Network IOCs - Domains: cdn.phototagx.com, www.roomako.com, lgaircon.xyz Network IOCs - URLs: https://www.roomako.com/jquery-3.3.1.min.js, … Network IOCs - IPs: 192.210.239.172

Advertisement

Organizations are advised to implement protective measures including the use of Cisco Secure Endpoint, Secure Firewall, and Umbrella to block malicious activity. Immediate patching of Cityworks systems and monitoring for listed IOCs are strongly recommended to mitigate this threat.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories