• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-sap-netweaver-bug-to-deploy-linux-auto-color-malware/

Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware

BleepingComputer
·
Bill Toulas
·
Published Jul 29, 2025
·
Updated

Hackers were spotted exploiting a critical SAP NetWeaver vulnerability tracked as CVE-2025-31324 to deploy the Auto-Color Linux malware in a cyberattack on a U.S.-based chemicals company. Cybersecurity firm Darktrace discovered the attack during an incident response in April 2025, where an investigation revealed that the Auto-Color malware had evolved to include additional advanced evasion tactics. Darktrace reports that the attack started on April 25, but active exploitation occurred two days later, delivering an ELF (Linux executable) file onto the targeted machine. The Auto-Color malware was first documented by Palo Alto Networks' Unit 42 researchers in February 2025, who highlighted its evasive nature and difficulty in eradicating once it has established a foothold on a machine. The backdoor adjusts its behavior based on the user privilege level it runs from, and uses 'ld.so.preload' for stealthy persistence via shared object injection. Auto-Color features capabilities such as arbitrary command execution, file modification, reverse shell for full remote access, proxy traffic forwarding, and dynamic configuration updating. It also has a rootkit module that hides its malicious activities from security tools. Unit 42 could not discover the initial infection vector from the attacks it observed, targeting universities and government organizations in North America and Asia. According to the latest research by Darktrace, the threat actors behind Auto-Color exploit CVE-2025-3132...

Read full article

Affected Software

1 affected component
SAP NetWeaver
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cybersecurity incident where hackers exploited a vulnerability in SAP NetWeaver to deploy Linux Auto-Color malware.

2

What security implications are discussed?

The exploitation of the SAP NetWeaver vulnerability poses significant risks to organizations using this software, potentially leading to unauthorized access and data breaches.

3

What vulnerability is being exploited?

The vulnerability being exploited is tracked as CVE-2025-31324 in SAP NetWeaver.

4

Which company was targeted in the cyberattack?

The cyberattack targeted a U.S.-based chemicals company.

5

What malware was deployed during the cyberattack?

The hackers deployed Linux Auto-Color malware as part of the cyberattack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203