Knowledge Centre
Home / News / Cyber Insurance News / Chinese APTs Exploit SAP Flaw to Breach Global Critical Infrastructure

Chinese APTs Exploit SAP Flaw to Breach Global Critical Infrastructure

Published on May 15, 2025. EST READ TIME: 2 minutes

Chinese APTs Exploit SAP Flaw to Breach Global Critical Infrastructure

Multiple China-linked advanced persistent threat (APT) groups are actively exploiting CVE-2025-31324, a critical unauthenticated file upload vulnerability in SAP NetWeaver’s Visual Composer component. This flaw enables remote code execution, allowing attackers to deploy web shells and maintain persistent access to compromised systems. Security researchers have identified at least 581 breached SAP instances, with targets spanning natural gas networks, water utilities, medical device manufacturers, and government agencies in countries including the UK, US, and Saudi Arabia.

The attacks have been attributed to Chinese APT groups such as UNC5221, UNC5174, and CL-STA-0048, who have used tools like KrustyLoader, SNOWLIGHT, and GOREVERSE to establish long-term access and exfiltrate data. SAP released a patch for the vulnerability on April 24, 2025, but many systems remain unpatched. Organizations are urged to apply the patch immediately and review their systems for signs of compromise.

Awards & Recognition
Image

BFSI Leadership Awards 2022 - Product Innovator of the Year (Optima Secure)

ETBFSI Excellence Awards 2021

FICCI Insurance Industry
Awards September 2021

ICAI Awards 2015-16

SKOCH Order-of-Merit

Best Customer Experience
Award of the Year

ICAI Awards 2014-15

Image

CMS Outstanding Affiliate World-Class Service Award 2015

Image

iAAA rating

Image

ISO Certification

Image

Best Insurance Company in Private Sector - General 2014

View all awards