Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware

Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware

Cyber threat actors exploited a patched SAP NetWeaver vulnerability to deploy the Auto-Color backdoor during an attack on a US-based chemicals company. The malware, capable of remote access, evades detection and has targeted organizations across North America and Asia. #CVE-2025-31324 #Auto-ColorBackdoor

Keypoints

  • A critical SAP NetWeaver flaw (CVE-2025-31324) was exploited before it was patched in April 2025.
  • Threat actors gained access to a network, downloaded suspicious files, and communicated with malicious C2 infrastructure.
  • The Auto-Color malware functions similar to a remote access trojan with advanced evasion capabilities.
  • Auto-Color can hide when unable to connect to its command-and-control servers to avoid detection.
  • The attack involved exploiting internet-facing SAP systems to deploy malware in early May 2025.

Read More: https://thehackernews.com/2025/07/hackers-exploit-sap-vulnerability-to.html