logo

Chinese Hackers Leverage SAP RCE Vulnerability to Install Supershell Backdoors

ID: 9fa8099f-c2ae-53bd-b09d-1059da3659b2

STIX ID: report--9fa8099f-c2ae-53bd-b09d-1059da3659b2

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-05-09

Date Updated: 2026-04-19

Author: Mandvi

...
...

A critical deserialization flaw (CVE-2025-31324) in SAP NetWeaver Visual Composer 7.x is being actively exploited to achieve unauthenticated RCE via the /developmentserver/metadatauploader endpoint, allowing attackers to deploy web shells (e.g., helper.jsp, cache.jsp), Supershell backdoors, and other tooling; Forescout links mass scanning and targeted exploitation to a Chinese-speaking group (Chaya_004), documents over 500 infrastructure IPs (including Chinese cloud providers) and multiple IoCs, and urges immediate patching (April 2025 NetWeaver AS Java fixes), endpoint restriction, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.