logo

Chinese hackers behind attacks targeting SAP NetWeaver servers

ID: 877ffaba-ac5d-59a8-939d-cb9c79c2db36

STIX ID: report--877ffaba-ac5d-59a8-939d-cb9c79c2db36

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2025-05-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Forescout and other security firms observed active exploitation of a critical SAP NetWeaver Visual Composer zero-day (CVE-2025-31324) that permits unauthenticated file uploads; attackers have been uploading JSP web shells and post-exploitation tools, compromising hundreds of exposed instances. The activity—dated from at least January–March 2025—has been linked to a Chinese threat actor tracked as Chaya_004, prompting emergency patches and CISA inclusion of the CVE in its Known Exploited Vulnerabilities Catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.