Chinese Hackers Leverage SAP RCE Vulnerability to Install Supershell Backdoors
ID: 9fa8099f-c2ae-53bd-b09d-1059da3659b2
STIX ID: report--9fa8099f-c2ae-53bd-b09d-1059da3659b2
Feed Name: Cyber Press
A critical deserialization flaw (CVE-2025-31324) in SAP NetWeaver Visual Composer 7.x is being actively exploited to achieve unauthenticated RCE via the /developmentserver/metadatauploader endpoint, allowing attackers to deploy web shells (e.g., helper.jsp, cache.jsp), Supershell backdoors, and other tooling; Forescout links mass scanning and targeted exploitation to a Chinese-speaking group (Chaya_004), documents over 500 infrastructure IPs (including Chinese cloud providers) and multiple IoCs, and urges immediate patching (April 2025 NetWeaver AS Java fixes), endpoint restriction, and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
