Zero-Day Vulnerability in SAP NetWeaver Used by Chinese Hackers to Attack Critical Systems

Zero-Day Vulnerability in SAP NetWeaver Used by Chinese Hackers to Attack Critical Systems

In April 2025, a groundbreaking discovery revealed a highly sophisticated cyberattack targeting critical infrastructure across the globe. This attack exploited an unreported vulnerability within SAP NetWeaver Visual Composer.

Designated as CVE-2025-31324, this flaw allowed unauthorized attackers to upload malicious files, granting them remote code execution access to compromised systems without needing any user authentication or special permissions.

The scope of the attacks was wide-ranging, with significant impacts on the United Kingdom’s natural gas distribution networks, water management services, medical device manufacturing facilities in the United States, oil and gas production operations, and government ministries in Saudi Arabia.

Reports indicate that these SAP systems were integrated with industrial control systems (ICS), heightening the risks associated with the breaches.

Investigations into the attacker’s infrastructure revealed connections to several Chinese-linked Advanced Persistent Threat (APT) groups, including UNC5221, UNC5174, and CL-STA-0048.

EclecticIQ Threat Intelligence – SAP NetWeaver Breaches (Source – EclecticIQ)

The threat actors responsible for these attacks are believed to have links to China’s Ministry of State Security (MSS) or associated private organizations, with clear strategic objectives to infiltrate and compromise critical infrastructure on a global scale.

EclecticIQ’s team uncovered an exposed directory on an attacker-controlled server (15.204.56.106), which contained detailed records of compromised systems and the malicious tools deployed during the operation.

Further analysis revealed that the server held two result files documenting over 581 SAP NetWeaver instances that had been breached and backdoored using webshells. Additionally, the server listed 1,800 domains running SAP NetWeaver, which were flagged as potential future targets.

The attackers exploited the “/developmentserver/metadatauploader” API endpoint in SAP NetWeaver, enabling them to upload harmful webshells and establish continuous remote access.

EclecticIQ’s researchers identified two key webshells used in the attacks: coreasp.jsp and forwardsap.jsp.

Analysis of the Webshell Payloads

The more complex of the two, coreasp.jsp, utilized sophisticated obfuscation and encryption strategies, designed to evade detection and hinder efforts to identify and neutralize the threat.

Coreasp Webshell Source Code Analysis (Source – EclecticIQ)

The webshell and its encryption method exposed in the code:

This simple yet effective backdoor listens for system commands passed through a parameter called “cmdhghgghhdd” and sends the results directly to the browser. This functionality serves as a backup access mechanism in case the primary encrypted communication channel is disrupted.

EclecticIQ analysts observed that the design and behavior of the webshell are strikingly similar to Behinder/冰蝎 v3, a tool commonly employed by Chinese-language cybercriminal groups. This connection further suggests that the attackers behind the campaign are likely linked to Chinese-based threat operators.

More Articles & Posts