logo

China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures

ID: a6d0405d-518b-5b10-9bbc-018428e2acd7

STIX ID: report--a6d0405d-518b-5b10-9bbc-018428e2acd7

Feed Name: EclecticIQ

Threat Score
90/100

Date Published: 2025-05-13

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

EclecticIQ reports that China‑nexus APTs actively exploited an unauthenticated file‑upload vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) to deploy webshells and multi‑stage malware (KrustyLoader, SNOWLIGHT, VShell), compromising hundreds of systems across critical infrastructure sectors worldwide; the report includes observed C2/IOCs, attacker TTPs, victimology, and mitigation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.