Critical SAP NetWeaver Flaw Weaponized: Advanced Auto-Color Malware Infiltrates U.S. Chemical Giant


# Hackers Exploit Critical SAP Vulnerability to Deploy Advanced Linux Malware

Cybersecurity researchers have uncovered a sophisticated cyberattack targeting a U.S. chemicals company, where hackers exploited a critical SAP NetWeaver vulnerability to deploy the Auto-Color Linux malware.

## The Attack Timeline

Darktrace, the cybersecurity firm that discovered the breach during an April 2025 incident response, revealed that attackers began their assault on April 25, with active exploitation occurring two days later. The attack leveraged CVE-2025-31324, a critical vulnerability in SAP NetWeaver that allows unauthenticated attackers to upload malicious files and execute remote code.

## Auto-Color Malware: A Sophisticated Threat

First documented by Palo Alto Networks’ Unit 42 researchers in February 2025, Auto-Color represents a highly evasive Linux malware with advanced capabilities:

– **Adaptive behavior** based on user privilege levels
– **Stealthy persistence** through shared object injection
– **Multiple attack functions** including command execution, file modification, reverse shell access, and proxy traffic forwarding
– **Rootkit capabilities** that hide malicious activities from security tools

## New Evasion Tactics Discovered

Darktrace’s investigation revealed a previously unknown evasion technique in Auto-Color’s latest version. If the malware cannot connect to its command-and-control (C2) server, it suppresses its malicious behavior, appearing benign to security analysts. This makes it particularly dangerous in sandboxed or air-gapped environments where researchers typically analyze threats.

“This behavior prevents reverse engineering efforts from uncovering its payloads, credential harvesting mechanisms, or persistence techniques,” Darktrace explained.

## Widespread Exploitation Campaign

The vulnerability has attracted significant attention from cybercriminals:

– **Initial targets**: Universities and government organizations across North America and Asia
– **Escalation**: By May 2025, ransomware groups and Chinese state-sponsored hackers joined the exploitation efforts
– **Zero-day activity**: Mandiant reported evidence of attacks dating back to mid-March 2025, before the vulnerability was publicly disclosed

## Critical Response Required

SAP released security patches in April 2025, but the rapid adoption by multiple threat actor groups highlights the urgency for organizations to act. Security firms ReliaQuest, Onapsis, and watchTowr have all reported active exploitation attempts in the wild.

System administrators running SAP NetWeaver should immediately apply the security updates provided in SAP’s customer bulletin or implement recommended mitigations to prevent compromise.

The Auto-Color malware’s evolution demonstrates how quickly cybercriminals adapt their tools to exploit new vulnerabilities, making rapid patch deployment essential for organizational security.

Share This Article