• News/
  • https://www.bleepingcomputer.com/news/security/chinese-hackers-behind-attacks-targeting-sap-netweaver-servers/

Chinese hackers behind attacks targeting SAP NetWeaver servers

BleepingComputer
·
Sergiu Gatlan
·
Published May 9, 2025
·
Updated

Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor. SAP released an out-of-band emergency patch on April 24 to address this unauthenticated file upload security flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer, days after cybersecurity company ReliaQuest first detected the vulnerability being targeted in attacks. Successful exploitation enables unauthenticated attackers to upload malicious files without logging in, allowing them to gain remote code execution and potentially leading to complete system compromise. ReliaQuest reported that multiple customers' systems were breached through unauthorized file uploads on SAP NetWeaver, with the threat actors uploading JSP web shells to public directories, as well as the Brute Ratel red team tool in the post-exploitation phase of their attacks. The compromised SAP NetWeaver servers were fully patched, indicating that the attackers used a zero-day exploit. This exploitation activity was also confirmed by other cybersecurity firms, including watchTowr and Onapsis, who also confirmed the attackers were uploading web shell backdoors on unpatched instances exposed online. Mandiant also observed CVE-2025-31324 zero-day attacks dating back to at least mid-March 2025, while Onapsis updated its original report to say its honeypot first captured reconnaissance activity and payload testing since January 20...

Read full article

Affected Software

3 affected components
SAP NetWeaver
SAP NetWeaver Visual Composer
SAP NetWeaver Visual Composer
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203