UAT-8302 and its box full of malware
A hacking group linked to China is using a mix of custom malware to break into government computers in South America and southeastern Europe. They steal data, grab passwords, and keep access hidden for years.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Update availableFix recorded on Sep 4, 2026
- Affected versions
- before 15.8.9; before 23.10
- Weakness
- CWE-502Deserialization of Untrusted Data
- Exploit likelihood
- 31% in 30 daysEPSS, higher than 98% of known flaws
- Affects
- Cityworks+1 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Feb 7, 2025
- Federal fix deadline
- Feb 28, 2025
How it works
- The attackers first break into government networks, then install multiple pieces of malware like NetDraft, CloudSorcerer, SNOWLIGHT, and SNOWRUST.
- These tools let them spy on files, steal passwords, and move deeper into the network using tools like Impacket and proxy software.
What to do
Check if your government office or related organization in South America or southeastern Europe has reported unusual network activity or data breaches since late 2024. Look for signs like unexpected slowdowns, strange files named NetDraft. exe or SNOWRUST. dll, or unfamiliar tools running in Task Manager.
If you work for a government agency in those regions, contact your IT security team immediately and run a full system scan for malware. Report any suspicious activity to your local cybersecurity authority right away.
Technical details
Affected software: Cityworksby Trimble, Cityworks (with office companion)by Trimble
CVE-2025-0994 describes UAT-8302, a China-nexus advanced persistent threat (APT) group that has targeted government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The group deploys multiple custom malware families, including -based backdoor called NetDraft, which is a C variant of the FinalDraft/SquidDoor malware family. This malware is associated with known China-linked APT clusters such as Jewelbug (REF7707, CL-STA-0049, LongNosedGoblin).
Additionally, UAT-8302 employs an updated version of the CloudSorcerer backdoor, previously used against Russian government targets in 2024. The group also leverages VSHELL alongside its SNOWLIGHT stager and introduces a new Rust-based stager called SNOWRUST. Researchers assess with high confidence that UAT-8302 operates as a China-linked APT group focused on maintaining long-term access to government and related entities globally.
Post-compromise activities include information collection, credential extraction, and lateral movement, utilizing open-source tools like Impacket and proxying utilities alongside custom malware. The malware deployed by UAT-8302 links the group to other publicly documented China-linked threat clusters, suggesting operational collaboration.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- learn.assetlifecycle.trimble.com Vendor Advisory
- cisa.gov · icsa-25-037-04 Third Party Advisory US Government Resource
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource