UAT-8302 and its box full of malware

Published September 4, 2026 CVE-2025-0994

A hacking group linked to China is using a mix of custom malware to break into government computers in South America and southeastern Europe. They steal data, grab passwords, and keep access hidden for years.

Severity
HighCVSS 3.1 · 8.8
Fix
Update availableFix recorded on Sep 4, 2026
Affected versions
before 15.8.9; before 23.10
Weakness
CWE-502Deserialization of Untrusted Data
Exploit likelihood
31% in 30 daysEPSS, higher than 98% of known flaws
Affects
Cityworks+1 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Feb 7, 2025
Federal fix deadline
Feb 28, 2025

How it works

  • The attackers first break into government networks, then install multiple pieces of malware like NetDraft, CloudSorcerer, SNOWLIGHT, and SNOWRUST.
  • These tools let them spy on files, steal passwords, and move deeper into the network using tools like Impacket and proxy software.

What to do

Check if your government office or related organization in South America or southeastern Europe has reported unusual network activity or data breaches since late 2024. Look for signs like unexpected slowdowns, strange files named NetDraft. exe or SNOWRUST. dll, or unfamiliar tools running in Task Manager.

If you work for a government agency in those regions, contact your IT security team immediately and run a full system scan for malware. Report any suspicious activity to your local cybersecurity authority right away.

Technical details

Affected software: Cityworksby Trimble, Cityworks (with office companion)by Trimble

CVE-2025-0994 describes UAT-8302, a China-nexus advanced persistent threat (APT) group that has targeted government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The group deploys multiple custom malware families, including -based backdoor called NetDraft, which is a C variant of the FinalDraft/SquidDoor malware family. This malware is associated with known China-linked APT clusters such as Jewelbug (REF7707, CL-STA-0049, LongNosedGoblin).

Additionally, UAT-8302 employs an updated version of the CloudSorcerer backdoor, previously used against Russian government targets in 2024. The group also leverages VSHELL alongside its SNOWLIGHT stager and introduces a new Rust-based stager called SNOWRUST. Researchers assess with high confidence that UAT-8302 operates as a China-linked APT group focused on maintaining long-term access to government and related entities globally.

Post-compromise activities include information collection, credential extraction, and lateral movement, utilizing open-source tools like Impacket and proxying utilities alongside custom malware. The malware deployed by UAT-8302 links the group to other publicly documented China-linked threat clusters, suggesting operational collaboration.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References