Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-6382

Also known as: VShell, tracked as, Silence.Downloader, pULB113

Description

UAT‑6382 surfaced in early 2025 as a highly technical actor that abused a public‑facing Cityworks vulnerability (CVE‑2025‑0944/0994) to enter enterprise networks. Once inside, the actors rapidly enumerate directories and deploy a suite of web shells—AntSword, chinatso/Chopper, Behinder—and custom file uploaders on compromised IIS servers. To achieve persistence they build Rust‑based loaders (TetraLoader built with MaLoader), which deliver advanced backdoors such as Cobalt Strike and the actor’s own VShell stager. The VShell component establishes a hardcoded C2 endpoint, drops in-memory payloads, and continuously scans for files of interest to stage data exfiltration. The group routinely performs reconnaissance and pivots toward utility management infrastructures, implying an emphasis on operational sabotage or strategic intelligence gathering against critical sectors. Their use of PowerShell scripts, web‑shell deployment, and Rust loaders illustrates a blend of commodity and custom malware that enables stealthy persistence and rapid lateral movement within the targeted environments. While specific indicators—such as hardcoded C2 addresses, Chinese language messages in web shells, and Rust binaries—provide actionable detection points, some details such as precise mission objectives or extended campaign timelines remain uncertain due to limited publicly available reporting.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Financial services
Energy
Manufacturing
Mining
Transportation
Healthcare
Nuclear
Food agriculture
Chemical

Targeted Countries / Regions

US
UA
CN
RU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 8 hours ago

Executive Summary

UAT‑6382 is a Chinese‑speaking threat actor that leverages zero‑day vulnerabilities in Cityworks (CVE‑2025‑0944/0994) to gain initial footholds, after which it deploys web shells and Rust‑based loaders to maintain persistence. The group targets critical infrastructure sectors—including utilities, energy, transportation, healthcare, and government—primarily within the U.S., Ukraine, China, and Russia, using sophisticated command‐and‐control channels and lateral movement tactics to pivot toward utility management systems.

Goals & Targeting

UAT‑6382 focuses on infiltrating and compromising control systems in the utilities and critical infrastructure sectors. By exploiting zero‐day vulnerabilities in widely deployed city management software and deploying web shells that persist via Rust loaders, the actor seeks long‐term access for data exfiltration, sabotage, or strategic espionage. The organization’s preference for targeting entities in the U.S., Ukraine, China, and Russia suggests a geopolitical agenda aimed at undermining perceived adversaries while securing financial gain from ransom or targeted theft. The attacker’s tactical profile—rapid reconnaissance, staged pivots to utility systems, and the use of powerful Cobalt Strike footholds—indicates an intent to maintain covert presence until mission objectives are achieved or until higher‑value targets become available. Their focus on utility management highlights a broader industry trend wherein actors seek control over or surveillance of power grids, water supply networks, and other essential services, exploiting the inherent interconnectivity of modern critical infrastructure.

Enhanced Description

Key Capabilities

  • Exploits Cityworks CVE-2025-0994 (and CVE-2025-0944) for initial access
  • Deploys web shells including AntSword, chinatso/Chopper, Behinder, and generic file uploaders on compromised IIS servers
  • Uses Rust-based loaders (TetraLoader via MaLoader framework) to deliver payloads such as Cobalt Strike and VShell
  • Performs rapid reconnaissance and directory enumeration after compromise
  • Stages exfiltrated data by copying files into directories where web shells are deployed
  • Maintains long‑term persistence via the VShell stager and backend C2 infrastructure
  • Targets utilities management systems for pivoting and lateral movement
  • Exploits public-facing vulnerability CVE-2025-0944 for initial exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Discovery
Lateral Movement

ATT&CK Techniques

T1497
T1179
T1190
T1059.001
T1105
T1074
T1021

Software / Tooling

Cityworks CVE-2025-0994 vulnerability
AntSword web shell
chinatso/Chopper web shell
Behinder web shell
VShell stager
TetraLoader loader
MaLoader framework
Cobalt Strike
PowerShell

Campaigns & Victims

UAT‑6382 has exhibited a consistent pattern of leveraging recently disclosed zero‑day vulnerabilities in Cityworks to break into government and critical infrastructure environments. After establishing footholds through web shells, the actor escalates privileges, deploys custom Rust loaders, and installs robust command-and-control agents (Cobalt Strike/Vshell). The operations show high operational tempo with rapid reconnaissance, pivoting toward utility management assets, and preparing data staging points for exfiltration. The group tends to operate within geographically diverse regions—primarily the U.S., Ukraine, China, and Russia—suggesting a cross‑border reach but focused on sectors that are often exposed through publicly accessible web services. Although only limited case studies exist, past incidents indicate an emphasis on long‑term persistence rather than immediate payoff, relying on advanced malware to remain undetected while the attacker selects high-value targets. Notable operations include the exploitation of CVE-2025-0944 (Cityworks) for initial access and subsequent deployment of web shells capable of executing PowerShell scripts that instantiate TetraLoader. The actor’s persistent backdoors and exploitation of utility control systems underscore its potential to disrupt operational technology networks if left unchecked.

IOC Patterns

  • Web shell deployment on ASP/IIS servers with Chinese language messages
  • Rust-based binary loader (TetraLoader) executed via PowerShell scripts
  • Exploitation of CVE-2025-0944 for initial access
  • Hardcoded C2 server connections used by VShell stager

Recommended Actions

  • Apply the Cityworks security patch for CVE-2025-0944 immediately
  • Disable or tightly secure ASP‑based web shells such as AntSword, chinatso/Chopper and Behinder on IIS servers
  • Monitor system logs for anomalous PowerShell activity and execution of downloaded stagers
  • Block known hardcoded C2 addresses used by VShell
  • Segment utility management networks to limit lateral movement
  • Implement IDS signatures for common web shell payloads
  • Monitor network traffic for unfamiliar web shell activity and anomalous file uploads
  • Implement log analysis of remote service usage

Suggested Tags

Chinese‑speaking threat actor
APT
Zero‑day exploitation
Web shells
Rust-based loader
Cobalt Strike
Cityworks CVE-2025-0944
UAT-6382
Utility sector targeting
CVE-2025-0944
WebShell
UtilityManagementTarget
CustomMalware

Confidence Assessment

The available intelligence provides a moderate level of confidence regarding UAT‑6382’s tactics, techniques, and objectives. Most observations stem from a limited number of reports that describe zero‑day exploitation, web shell deployment, and Rust‑based loaders. Key gaps remain in the actor’s exact operational timeline, the full extent of financial motivations versus geopolitical aims, and corroborating evidence across multiple independent sources. Future monitoring should validate these indicators against additional hunting data to refine the threat model.

ATT&CK Techniques

Collection
1 technique
Command & Control
1 technique
Execution
1 technique
Lateral Movement
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: Carbon
  2. blog.talosintelligence.com — Cited by web research for: TetraLoader
  3. blog.talosintelligence.com — Cited by web research for: Unknown
  4. thehackernews.com — Cited by web research for: CVE-2026-50522

Intel Summary

7

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
Backdoor / C2
espionage
government
local bodies
Chinese‑speaking threat actor
Zero‑day exploitation
Web shells
Rust-based loader
Cobalt Strike
Cityworks CVE-2025-0944
UAT-6382
Utility sector targeting
CVE-2025-0944
WebShell
UtilityManagementTarget
CustomMalware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.