Cyber threat actors exploited a patched SAP NetWeaver vulnerability to deploy the Auto-Color backdoor during an attack on a US-based chemicals company. The malware, capable of remote access, evades detection and has targeted organizations across North America and Asia. #CVE-2025-31324 #Auto-ColorBackdoor
Keypoints
- A critical SAP NetWeaver flaw (CVE-2025-31324) was exploited before it was patched in April 2025.
- Threat actors gained access to a network, downloaded suspicious files, and communicated with malicious C2 infrastructure.
- The Auto-Color malware functions similar to a remote access trojan with advanced evasion capabilities.
- Auto-Color can hide when unable to connect to its command-and-control servers to avoid detection.
- The attack involved exploiting internet-facing SAP systems to deploy malware in early May 2025.
Read More: https://thehackernews.com/2025/07/hackers-exploit-sap-vulnerability-to.html