{"id":5748,"date":"2025-07-30T10:08:29","date_gmt":"2025-07-30T10:08:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/30\/hackers-exploiting-sap-netweaver-vulnerability-to-deploy-auto-color-linux-malware\/"},"modified":"2025-07-30T10:08:29","modified_gmt":"2025-07-30T10:08:29","slug":"hackers-exploiting-sap-netweaver-vulnerability-to-deploy-auto-color-linux-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/30\/hackers-exploiting-sap-netweaver-vulnerability-to-deploy-auto-color-linux-malware\/","title":{"rendered":"Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware"},"content":{"rendered":"<p>    Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with <a href=\"https:\/\/cybersecuritynews.com\/auto-color-linux-backdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\">Auto-Color malware<\/a>, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.\u00a0<\/p>\n<p>In April 2025, cybersecurity firm Darktrace successfully detected and contained an attack that exploited CVE-2025-31324, a critical vulnerability in SAP NetWeaver, to deploy the stealthy Auto-Color backdoor malware over three days.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. CVE-2025-31324 SAP NetWeaver attack deployed Auto-Color malware.<br>2. Auto-Color uses Linux manipulation and adaptive evasion techniques.<br>3. Darktrace prevented malware activation and C2 communication.<\/pre>\n<h2 class=\"wp-block-heading\">\n<strong>\u00a0SAP NetWeaver Vulnerability<\/strong> <strong>Exploited<\/strong><br \/>\n<\/h2>\n<p>The attack began with the exploitation of <a href=\"https:\/\/cybersecuritynews.com\/sap-may-2025-patch-tuesday\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-31324<\/a>, a critical vulnerability disclosed by SAP SE on April 24, 2025, that affects SAP NetWeaver application servers.\u00a0<\/p>\n<p>This vulnerability enables malicious actors to upload files to the server, potentially leading to remote code execution and full system compromise.\u00a0<\/p>\n<p>Threat actors conducted reconnaissance activities starting April 25, scanning for the vulnerability using URIs containing \/developmentserver\/metadatauploader before launching the full attack two days later.<\/p>\n<p>The initial compromise occurred through a ZIP file download from a malicious IP address 91.193.19[.]109, accompanied by DNS tunneling requests to Out-of-Band <a href=\"https:\/\/cybersecuritynews.com\/dynamic-application-security-testing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Application Security Testing<\/a> (OAST) domains such as aaaaaaaaaaaa[.]d06oojugfd4n58p4tj201hmy54tnq4rak[.]oast[.]me.\u00a0<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdAYuzz4nIjeykFhdbmS0tzs2JoJCLVvLCgm64Bd0E4rNp0NOMgRGxFmKsOlHCcFkCDJoVVTFGc14ne8zgL5Q9nOmmtsnvDOcyEGCm2u7jqXu_wlp1bs-56LSLKgdPh-QzquM2WmA?key=wFwiw10x-fh6l551shfwQg\" alt=\"\"><\/figure>\n<p>The attackers then executed a shell script named config.sh via the helper.jsp file, establishing connections to C2 infrastructure at 47.97.42[.]177 over port 3232, an endpoint associated with Supershell, a command-and-control platform linked to China-affiliated threat groups.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Auto-Color Malware Persistence Techniques<\/strong><\/h2>\n<p>The Auto-Color backdoor malware, named after its ability to rename itself to \/var\/log\/cross\/auto-color after execution, represents a sophisticated <a href=\"https:\/\/cybersecuritynews.com\/tag\/remote-access-trojan\/\" target=\"_blank\" rel=\"noreferrer noopener\">Remote Access Trojan (RAT)<\/a> that has primarily targeted universities and government institutions since November 2024.\u00a0<\/p>\n<p>The malware demonstrates adaptive behavior based on privilege levels, with limited functionality when executed without root privileges to avoid detection in restricted environments.<\/p>\n<p>When executed with root privileges, Auto-Color performs invasive installation procedures, deploying a malicious shared object libcext.so.2 that masquerades as a legitimate C utility library.\u00a0<\/p>\n<p>The malware achieves persistence through ld.so.preload manipulation, modifying or creating \/etc\/ld.so.preload to insert references to the malicious library.\u00a0<\/p>\n<p>This technique ensures the malware loads before other libraries when executing dynamically linked programs, enabling it to hook and override standard system functions across applications.<\/p>\n<p>The successful intervention by Darktrace\u2019s Managed Detection and Response service, which extended Autonomous Response actions for an additional 24 hours, provided crucial time for the customer\u2019s security team to investigate and remediate the threat.\u00a0<\/p>\n<p>The attack underscores the urgent need for organizations using <a href=\"https:\/\/cybersecuritynews.com\/tag\/sap-netweaver\/\" target=\"_blank\" rel=\"noreferrer noopener\">SAP NetWeaver<\/a> to immediately apply security patches, as threat actors continue to exploit this critical vulnerability across multiple systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><code><strong>Integrate <strong>ANY.RUN TI Lookup<\/strong> with your SIEM or SOAR To Analyses Advanced Threats<\/strong> -&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=atricle&amp;utm_campaign=want-to-detect-incidents-before&amp;utm_content=plans1&amp;utm_term=290725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Free Trial Searches<\/a> <\/strong><\/code><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sap-netweaver-vulnerability-exploited-malware\/\">Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sap-netweaver-vulnerability-exploited-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.\u00a0 In April 2025, cybersecurity firm Darktrace successfully detected [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63,131],"tags":[130],"class_list":["post-5748","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5748"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5748"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5748\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}