Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor. SAP released an out-of-band emergency patch on April 24 to address this unauthenticated file upload security flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer, days after cybersecurity company ReliaQuest first detected the vulnerability being targeted in attacks. Successful exploitation enables unauthenticated attackers to upload malicious files without logging in, allowing them to gain remote code execution and potentially leading to complete system compromise. ReliaQuest reported that multiple customers' systems were breached through unauthorized file uploads on SAP NetWeaver, with the threat actors uploading JSP web shells to public directories, as well as the Brute Ratel red team tool in the post-exploitation phase of their attacks. The compromised SAP NetWeaver servers were fully patched, indicating that the attackers used a zero-day exploit. This exploitation activity was also confirmed by other cybersecurity firms, including watchTowr and Onapsis, who also confirmed the attackers were uploading web shell backdoors on unpatched instances exposed online. Mandiant also observed CVE-2025-31324 zero-day attacks dating back to at least mid-March 2025, while Onapsis updated its original report to say its honeypot first captured reconnaissance activity and payload testing since January 20...
Chinese hackers behind attacks targeting SAP NetWeaver servers
BleepingComputer
·Sergiu Gatlan
·Published May 9, 2025
·Updated
Affected Software
3 affected components
SAP NetWeaver
SAP NetWeaver Visual Composer
SAP NetWeaver Visual Composer