{"id":3862,"date":"2025-05-10T10:03:54","date_gmt":"2025-05-10T10:03:54","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/10\/chinese-hackers-exploit-sap-rce-vulnerability-to-upload-supershell-backdoors\/"},"modified":"2025-05-10T10:03:54","modified_gmt":"2025-05-10T10:03:54","slug":"chinese-hackers-exploit-sap-rce-vulnerability-to-upload-supershell-backdoors","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/10\/chinese-hackers-exploit-sap-rce-vulnerability-to-upload-supershell-backdoors\/","title":{"rendered":"Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors"},"content":{"rendered":"<p>    Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/google-patched-linux-kernel-vulnerability-in-android\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a> allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable \/developmentserver\/metadatauploader endpoint.<\/p>\n<p>Exploitation has been observed primarily targeting manufacturing environments, where compromised SAP systems could lead to significant operational disruptions and security breaches.<\/p>\n<p>The threat actor, tracked as Chaya_004, has been leveraging this vulnerability since at least April 29, 2025, shortly after proof-of-concept exploits became publicly available.<\/p>\n<p>Their attack infrastructure heavily utilizes Chinese cloud providers, including Alibaba, Tencent, and Huawei Cloud Services.<\/p>\n<p>This campaign demonstrates a sophisticated approach to infrastructure deployment, with over 700 identified IP addresses sharing consistent configuration patterns.<\/p>\n<p>Forescout researchers <a href=\"https:\/\/www.forescout.com\/blog\/threat-analysis-sap-vulnerability-exploited-in-the-wild-by-chinese-threat-actor\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malicious infrastructure after recovering an ELF binary named \u201cconfig\u201d from one of the attacks.<\/p>\n<p>The binary contained an IP address hosting a SuperShell login interface, which led to the discovery of hundreds of additional IP addresses sharing unusual certificate configurations.<\/p>\n<p>The certificates utilized anomalous self-signed properties impersonating <a href=\"https:\/\/cybersecuritynews.com\/cloudflare-developer-domains-abused\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare<\/a> with a distinctive subject DN attribute.<\/p>\n<p>The exploitation pattern involves POST requests to the vulnerable endpoint, followed by the deployment of web shells with names such as \u201chelper.jsp,\u201d \u201ccache.jsp,\u201d or randomized eight-letter filenames like \u201cssonkfrd.jsp.\u201d<\/p>\n<p>Once established, these backdoors enable attackers to download additional malicious payloads using curl commands, as demonstrated in the following attack sequence:-<\/p>\n<pre class=\"wp-block-code\"><code>POST \/developmentserver\/metadatauploader HTTP\/1.1\nHost: [target]\nContent-Type: multipart\/form-data; boundary=---------------------------9051914041544843365972754266\nContent-Length: [length]\n\n-----------------------------9051914041544843365972754266\nContent-Disposition: form-data; name=\"file\"; filename=\"webshell.jsp\"\nContent-Type: application\/octet-stream\n\n\n\n-----------------------------9051914041544843365972754266--<\/code><\/pre>\n<p>The deployed SuperShell backdoors provide attackers with comprehensive system access, allowing them to manipulate service endpoints, <a href=\"https:\/\/cybersecuritynews.com\/researchers-detailed-letmeowin-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">harvest credentials<\/a>, and potentially pivot to more critical SAP components.<\/p>\n<p>The primary backdoor interface was identified on port 8888 with the distinctive path \u201c\/supershell\/login\u201d across multiple compromised systems.<\/p>\n<p>Organizations running affected <a href=\"https:\/\/cybersecuritynews.com\/19-vulnerabilities-across-multiple-products-patched\/\" target=\"_blank\" rel=\"noreferrer noopener\">SAP<\/a> versions are strongly urged to apply the security patches released in the April 2025 Patch Day immediately.<\/p>\n<p>Additional recommended mitigations include restricting access to metadata uploader services, disabling unused web services, and implementing real-time monitoring for anomalous access to SAP systems, particularly outside of regular maintenance windows.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong>Are you from the SOC and DFIR Teams? \u2013 Analyse Real time Malware Incidents with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/app.any.run\/#register?utm_source=csn_may&amp;utm_medium=post&amp;utm_campaign=trends-q1-2025&amp;utm_content=blog&amp;utm_term=010525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-exploit-sap-rce-vulnerability\/\">Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-exploit-sap-rce-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide. The vulnerability allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable \/developmentserver\/metadatauploader endpoint. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,649,131],"tags":[130],"class_list":["post-3862","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-threats","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3862"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3862"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3862\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}