Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    Supercell revenue declines 4% to €2.65bn in 2025

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      HBAR Shorts Face $5 Million Risk if Price Breaks Key Level

      February 10, 2026

      Ethereum Holds $2,000 Support — Accumulation Keeps Recovery Hopes Alive

      February 10, 2026

      Miami Mansion Listed for 700 BTC as California Billionaire Tax Sparks Relocations

      February 10, 2026

      Solana Drops to 2-Year Lows — History Suggests a Bounce Toward $100 is Incoming

      February 10, 2026

      Bitget Cuts Stock Perps Fees to Zero for Makers Ahead of Earnings Season, Expanding Access Across Markets

      February 10, 2026
    • Technology

      OpenAI upgrades its Responses API to support agent skills and a complete terminal shell

      February 11, 2026

      ‘Observational memory’ cuts AI agent costs 10x and outscores RAG on long-context benchmarks

      February 11, 2026

      Is agentic AI ready to reshape Global Business Services?

      February 11, 2026

      OpenAI’s new Codex app hits 1M+ downloads in first week — but limits may be coming to free and Go users

      February 11, 2026

      Nvidia releases DreamDojo, a robot ‘world model’ trained on 44,000 hours of human video

      February 11, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Chinese hackers behind attacks targeting SAP NetWeaver servers
    Technology

    Chinese hackers behind attacks targeting SAP NetWeaver servers

    TechAiVerseBy TechAiVerseMay 10, 2025No Comments3 Mins Read5 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Chinese hackers behind attacks targeting SAP NetWeaver servers
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Chinese hackers behind attacks targeting SAP NetWeaver servers

    Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor.

    SAP released an out-of-band emergency patch on April 24 to address this unauthenticated file upload security flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer, days after cybersecurity company ReliaQuest first detected the vulnerability being targeted in attacks.

    Successful exploitation enables unauthenticated attackers to upload malicious files without logging in, allowing them to gain remote code execution and potentially leading to complete system compromise.

    ReliaQuest reported that multiple customers’ systems were breached through unauthorized file uploads on SAP NetWeaver, with the threat actors uploading JSP web shells to public directories, as well as the Brute Ratel red team tool in the post-exploitation phase of their attacks. The compromised SAP NetWeaver servers were fully patched, indicating that the attackers used a zero-day exploit.

    This exploitation activity was also confirmed by other cybersecurity firms, including watchTowr and Onapsis, who also confirmed the attackers were uploading web shell backdoors on unpatched instances exposed online.

    Mandiant also observed CVE-2025-31324 zero-day attacks dating back to at least mid-March 2025, while Onapsis updated its original report to say its honeypot first captured reconnaissance activity and payload testing since January 20, with exploitation attempts starting on February 10.

    The Shadowserver Foundation is now tracking 204 SAP Netweaver servers exposed online and vulnerable to CVE-2025-31324 attacks.

    Onyphe CTO Patrice Auffret also told BleepingComputer in late April that “Something like 20 Fortune 500/Global 500 companies are vulnerable, and many of them are compromised,” adding that at the time, there were 1,284 vulnerable instances exposed online, 474 of which were already compromised.

    Vulnerable SAP NetWeaver instances exposed online (Shadowserver Foundation)

    ​Attacks linked to Chinese hackers

    More recent attacks on April 29 have been linked to a Chinese threat actor tracked by Forescout’s Vedere Labs as Chaya_004.

    These attacks were launched from IP addresses using anomalous self-signed certificates impersonating Cloudflare, many of them belonging to Chinese cloud providers (e.g., Alibaba, Shenzhen Tencent, Huawei Cloud Service, and China Unicom).

    The attacker also deployed Chinese-language tools during the breaches, including a web-based reverse shell (SuperShell) developed by a Chinese-speaking developer.

    “As part of our investigation into active exploitation of this vulnerability, we uncovered malicious infrastructure likely belonging to a Chinese threat actor, which we are currently tracking as Chaya_004 – following our convention for unnamed threat actors,” Forescout said.

    “The infrastructure includes a network of servers hosting Supershell backdoors, often deployed on Chinese cloud providers, and various pen testing tools, many of Chinese origin.”

    SAP admins are advised to immediately patch their NetWeaver instances, restrict access to metadata uploader services, monitor for suspicious activity on their servers, and consider disabling the Visual Composer service if possible.

    CISA has also added the CVE-2025-31324 security flaw to its Known Exploited Vulnerabilities Catalog one week ago, ordering U.S. federal agencies to secure their systems against these attacks by May 20, as required by Binding Operational Directive (BOD) 22-01.

    “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleGermany takes down eXch cryptocurrency exchange, seizes servers
    Next Article Police dismantles botnet selling hacked routers as residential proxies
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    OpenAI upgrades its Responses API to support agent skills and a complete terminal shell

    February 11, 2026

    ‘Observational memory’ cuts AI agent costs 10x and outscores RAG on long-context benchmarks

    February 11, 2026

    Is agentic AI ready to reshape Global Business Services?

    February 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025664 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025151 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Gaming February 11, 2026

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business…

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    Supercell revenue declines 4% to €2.65bn in 2025

    Riot Games downsizes 2XKO team, about 80 employees affected

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    February 11, 20263 Views

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    February 11, 20262 Views

    Supercell revenue declines 4% to €2.65bn in 2025

    February 11, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.