Also known as: VShell, tracked as, Silence.Downloader, pULB113
UAT‑6382 surfaced in early 2025 as a highly technical actor that abused a public‑facing Cityworks vulnerability (CVE‑2025‑0944/0994) to enter enterprise networks. Once inside, the actors rapidly enumerate directories and deploy a suite of web shells—AntSword, chinatso/Chopper, Behinder—and custom file uploaders on compromised IIS servers. To achieve persistence they build Rust‑based loaders (TetraLoader built with MaLoader), which deliver advanced backdoors such as Cobalt Strike and the actor’s own VShell stager. The VShell component establishes a hardcoded C2 endpoint, drops in-memory payloads, and continuously scans for files of interest to stage data exfiltration. The group routinely performs reconnaissance and pivots toward utility management infrastructures, implying an emphasis on operational sabotage or strategic intelligence gathering against critical sectors. Their use of PowerShell scripts, web‑shell deployment, and Rust loaders illustrates a blend of commodity and custom malware that enables stealthy persistence and rapid lateral movement within the targeted environments. While specific indicators—such as hardcoded C2 addresses, Chinese language messages in web shells, and Rust binaries—provide actionable detection points, some details such as precise mission objectives or extended campaign timelines remain uncertain due to limited publicly available reporting.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑6382 is a Chinese‑speaking threat actor that leverages zero‑day vulnerabilities in Cityworks (CVE‑2025‑0944/0994) to gain initial footholds, after which it deploys web shells and Rust‑based loaders to maintain persistence. The group targets critical infrastructure sectors—including utilities, energy, transportation, healthcare, and government—primarily within the U.S., Ukraine, China, and Russia, using sophisticated command‐and‐control channels and lateral movement tactics to pivot toward utility management systems.
Goals & Targeting
UAT‑6382 focuses on infiltrating and compromising control systems in the utilities and critical infrastructure sectors. By exploiting zero‐day vulnerabilities in widely deployed city management software and deploying web shells that persist via Rust loaders, the actor seeks long‐term access for data exfiltration, sabotage, or strategic espionage. The organization’s preference for targeting entities in the U.S., Ukraine, China, and Russia suggests a geopolitical agenda aimed at undermining perceived adversaries while securing financial gain from ransom or targeted theft. The attacker’s tactical profile—rapid reconnaissance, staged pivots to utility systems, and the use of powerful Cobalt Strike footholds—indicates an intent to maintain covert presence until mission objectives are achieved or until higher‑value targets become available. Their focus on utility management highlights a broader industry trend wherein actors seek control over or surveillance of power grids, water supply networks, and other essential services, exploiting the inherent interconnectivity of modern critical infrastructure.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT‑6382 has exhibited a consistent pattern of leveraging recently disclosed zero‑day vulnerabilities in Cityworks to break into government and critical infrastructure environments. After establishing footholds through web shells, the actor escalates privileges, deploys custom Rust loaders, and installs robust command-and-control agents (Cobalt Strike/Vshell). The operations show high operational tempo with rapid reconnaissance, pivoting toward utility management assets, and preparing data staging points for exfiltration. The group tends to operate within geographically diverse regions—primarily the U.S., Ukraine, China, and Russia—suggesting a cross‑border reach but focused on sectors that are often exposed through publicly accessible web services. Although only limited case studies exist, past incidents indicate an emphasis on long‑term persistence rather than immediate payoff, relying on advanced malware to remain undetected while the attacker selects high-value targets. Notable operations include the exploitation of CVE-2025-0944 (Cityworks) for initial access and subsequent deployment of web shells capable of executing PowerShell scripts that instantiate TetraLoader. The actor’s persistent backdoors and exploitation of utility control systems underscore its potential to disrupt operational technology networks if left unchecked.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a moderate level of confidence regarding UAT‑6382’s tactics, techniques, and objectives. Most observations stem from a limited number of reports that describe zero‑day exploitation, web shell deployment, and Rust‑based loaders. Key gaps remain in the actor’s exact operational timeline, the full extent of financial motivations versus geopolitical aims, and corroborating evidence across multiple independent sources. Future monitoring should validate these indicators against additional hunting data to refine the threat model.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics