Qilin Targeted SAP Zero-Day Vulnerability Ahead of Public Release

Qilin Targeted SAP Zero-Day Vulnerability Ahead of Public Release

A severe vulnerability within SAP enterprise software, identified as CVE-2025-31324, was exploited by the Russian Ransomware-as-a-Service (RaaS) group Qilin nearly three weeks prior to its public disclosure, according to a recent analysis.

This critical flaw, which was assigned the highest possible CVSS score of 10.0, affects SAP NetWeaver Visual Composer, a widely used component in enterprise environments across the globe.

The vulnerability exists in the /developmentserver/metadatauploader endpoint, which lacks proper authentication enforcement. This oversight enables unauthenticated attackers to upload malicious files to vulnerable servers.

The danger posed by this vulnerability is twofold: its ease of exploitation and the pervasive use of SAP components in vital business systems. With no authentication requirements and exposure through standard HTTP/HTTPS protocols, the flaw presents a readily accessible attack surface. If exploited, attackers can gain remote code execution privileges, potentially compromising entire systems and deploying ransomware.

OP Innovate’s analysts discovered that Qilin had already exploited the flaw weeks before it was publicly known, during an incident response investigation for a major global company. Their forensic work revealed that this early exploitation indicated sophisticated intelligence gathering by the threat actor.

Despite some earlier reports suggesting involvement by Chinese-linked Advanced Persistent Threats (APTs), OP Innovate’s investigation definitively linked the attack to Qilin’s known infrastructure.

“Initially part of a routine post-disclosure investigation, this case quickly evolved into a rare and invaluable look into zero-day exploitation in real-world scenarios,” remarked the incident response team.

This incident underscores a troubling trend: financially driven cybercriminals like Qilin are increasingly adopting zero-day exploitation techniques that were once typical of nation-state actors. The pre-disclosure exploitation of CVE-2025-31324 signals a rapidly diminishing gap between vulnerability discovery and active exploitation.

Enterprise systems utilizing SAP are at heightened risk as these criminal groups adopt advanced tactics once reserved for state-sponsored attacks.

Exploitation Path and WebShell Deployment

The attack began with the exploitation of a misconfigured load balancer, which exposed internal SAP services to the internet. Qilin operators used the vulnerable /developmentserver/metadatauploader endpoint to upload several JSP-based webshells to the SAP IRJ directory.

These webshells, named randomly (e.g., randoml2.jsp, xxkmszdm.jsp, gpfmddkh.jsp), were automatically compiled by SAP into executable class files, granting attackers remote code execution access.

Once inside, the attackers used the webshells to execute PowerShell commands, which downloaded a SOCKS5 tunneling tool (rs64c.exe) from a known Qilin command and control server (184.174.96.74).

The command used was:

This payload was intended to establish a link to additional Qilin infrastructure at IP address 180.131.145.73, which matches indicators found in a previous threat intelligence report (IOC_QILIN Ransomware v1.3) from Indonesia’s National Cyber and Crypto Agency.

Fortunately, the organization’s defenses were successful in blocking the attack. Their firewall prevented outbound command-and-control traffic, and endpoint detection and response (EDR) systems isolated the malicious payloads before they could be executed.

Though the attackers attempted to erase their tracks by issuing Remove-Item commands, the files had already been quarantined by the security systems, preventing further damage.

Qilin’s Attack Sequence (Source – OP Innovate)

The analysis underscores the vital need for multi-layered security measures to safeguard enterprise middleware such as SAP. As ransomware groups elevate their tactics, leveraging advanced exploitation methods once linked to state-backed actors, organizations must adapt their defense strategies accordingly.

More Articles & Posts