UAT-6382
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
UAT-6382 is a Chinese-speaking threat actor that emerged in January 2025, primarily targeting US local government entities and critical utility management systems. This group is distinguished by its focused exploitation of a zero-day vulnerability, CVE-2025-0994, in Trimble Cityworks software to gain initial access. Their operations involve deploying custom Rust-based malware loaders, known as TetraLoader, built using the MaLoader framework, which contains Simplified Chinese language elements. While some reports initially suggested financial motivation, the specific targeting of critical infrastructure and utility management post-exploitation strongly indicates state-aligned objectives focused on cyber espionage and strategic disruption. There is no evidence suggesting the group operates under multiple names or is commonly confused with other threat actors.