Logo

Home

News

Cyber Insurance

Chinese Apts Exploit Sap Flaw To Breach Global Critical Infrastructure

Chinese APTs Exploit SAP Flaw to Breach Global Critical Infrastructure

Chinese APTs Exploit SAP Flaw to Breach Global Critical Infrastructure

Multiple China-linked advanced persistent threat (APT) groups are actively exploiting CVE-2025-31324, a critical unauthenticated file upload vulnerability in SAP NetWeaver’s Visual Composer component. This flaw enables remote code execution, allowing attackers to deploy web shells and maintain persistent access to compromised systems. Security researchers have identified at least 581 breached SAP instances, with targets spanning natural gas networks, water utilities, medical device manufacturers, and government agencies in countries including the UK, US, and Saudi Arabia.

The attacks have been attributed to Chinese APT groups such as UNC5221, UNC5174, and CL-STA-0048, who have used tools like KrustyLoader, SNOWLIGHT, and GOREVERSE to establish long-term access and exfiltrate data. SAP released a patch for the vulnerability on April 24, 2025, but many systems remain unpatched. Organizations are urged to apply the patch immediately and review their systems for signs of compromise.

Was this article helpful?

Easiest way to manage your HDFC ERGO policies is Here

Download our new mobile app Here to manage your insurance policies

Here QR

Scan To Download