Auto-Color Malware Uncovered: A Critical Threat Exploiting SAP NetWeaver on Linux Systems

Listen to this Post

Featured Image

Introduction: A New Cyber Threat on the Rise

In April 2025, cybersecurity experts uncovered a sophisticated backdoor malware campaign targeting Linux systems by exploiting a recently disclosed critical vulnerability in SAP NetWeaver. This malware, dubbed Auto-Color, was used in a highly targeted attack against a US-based chemicals company, highlighting an alarming escalation in cyber threats aimed at enterprise-grade software. The campaign leverages CVE-2025-31324, a remote file upload flaw in SAP’s Visual Composer Metadata Uploader, quickly weaponized by attackers to gain unauthorized access and control over vulnerable systems. This incident underscores the urgent need for organizations using SAP solutions to strengthen their security posture and coordinate efforts across IT and security teams.

The Attack Overview and Its Rapid Exploitation

The intrusion began when attackers exploited the CVE-2025-31324 vulnerability in SAP NetWeaver. Despite SAP’s public disclosure of this flaw on April 24, threat actors rapidly capitalized on the window of opportunity, delivering the malware within days. Using a malicious URI to push a ZIP file, the attackers initiated a sequence of suspicious network activity, including DNS tunneling and connections to known malicious domains. Within 24 hours, the Auto-Color malware was deployed as an ELF file downloaded from a remote server, effectively gaining remote access to the targeted Linux host.

Researchers from Darktrace were the first to document this exploitation and infection chain. The attack leveraged advanced persistence techniques by disguising the malware as a shared library file, libcext.so.2, manipulating the Linux ld.so.preload mechanism to maintain control even after system reboots. The malware adapts its behavior based on user privileges, installing more deeply when run with root access.

This backdoor maintains stealth through TLS-encrypted outbound connections to a hardcoded command-and-control (C2) server. If the connection cannot be established, Auto-Color remains dormant, evading sandbox detection or offline analysis.

What Makes Auto-Color Dangerous?

Auto-Color is a privilege-aware Remote Access Trojan (RAT) with modular capabilities, including reverse shell access, file execution, and even a kill switch to disable itself if needed. Its static, encrypted configuration embedded at compile time helps avoid detection and reverse engineering. Its ability to hide as legitimate log files and use advanced Linux persistence tactics makes it highly elusive.

Darktrace’s Autonomous Response system successfully blocked outbound C2 connections, preventing the malware from advancing beyond initial stages in the documented attack. Experts emphasize that defending SAP environments requires integrating SAP security within overall IT security frameworks, bridging gaps between SAP Basis teams and cybersecurity operations.

What Undercode Say: Understanding the Broader Implications

The discovery of Auto-Color’s use of a critical SAP NetWeaver vulnerability signals a shift in threat actor strategies and priorities. Historically, SAP systems have been considered high-value but relatively secure due to specialized infrastructure and the complex nature of their environments. However, this campaign reveals attackers are growing more adept at weaponizing even newly disclosed vulnerabilities quickly and with increasing technical sophistication.

Auto-Color’s exploitation of ld.so.preload for persistence is especially noteworthy. This method is rarely seen outside targeted attacks and requires deep knowledge of Linux internals, reflecting the attackers’ expertise. The malware’s modular design means it can be updated with new commands, allowing attackers to adapt to detection methods or pivot laterally within compromised networks. This flexibility elevates the threat beyond a simple backdoor.

The integration of DNS tunneling techniques and encrypted outbound communication channels highlights the attackers’ efforts to blend into legitimate network traffic, making detection through traditional perimeter security challenging. This case exemplifies why organizations must employ advanced behavioral detection systems like Darktrace’s AI-driven Autonomous Response to recognize anomalous activity swiftly.

Furthermore, the incident brings attention to a recurring gap in enterprise security: siloed responsibilities. SAP teams, often focused on system maintenance, may lack deep cybersecurity expertise, while IT security teams might not fully understand SAP-specific threats. The collaboration between these groups is critical, as vulnerabilities like CVE-2025-31324 impact both application and infrastructure layers.

From a strategic viewpoint, this attack stresses the importance of rapid vulnerability management and threat intelligence sharing. Organizations must act immediately on disclosures of critical flaws and adopt zero-trust models to limit the damage potential of such intrusions. Proactive threat hunting and network segmentation could also mitigate the risk posed by RATs like Auto-Color.

Lastly, this incident sends a clear message to vendors: timely patching is necessary but insufficient alone. Security products should incorporate real-time threat detection and automatic response capabilities to counter advanced persistent threats that evolve faster than traditional patch cycles.

🔍 Fact Checker Results

✅ Auto-Color exploits CVE-2025-31324 in SAP NetWeaver, confirmed by multiple cybersecurity firms.
✅ The malware uses ld.so.preload for persistence on Linux, a known advanced technique.
✅ Darktrace successfully blocked the malware’s outbound communications during the reported attack.

📊 Prediction: The Rising Tide of Targeted SAP Exploits

The Auto-Color campaign foreshadows an emerging trend where threat actors increasingly target specialized enterprise software like SAP with precision and speed. As vulnerabilities continue to be disclosed, attackers will likely intensify efforts to weaponize them before patches are widely adopted.

We can expect more malware strains adopting modular, privilege-aware designs that blend stealth and flexibility, targeting Linux and other critical infrastructure environments. This will drive demand for holistic security solutions that merge application security with network-level monitoring and autonomous incident response.

Organizations running SAP NetWeaver and similar platforms must prioritize integrating vulnerability management with AI-powered threat detection. Failure to adapt will leave critical industrial and commercial systems vulnerable to costly breaches and operational disruptions. The stakes are high, and the window to act is narrow.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon