Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Malware - New Malware “Auto-Color” Exploited in Live SAP NetWeaver Attack
Malware Attacks Data Protection Endpoint Security Latest News News & Analysis Threat Intelligence Threats and Vulnerabilities

New Malware “Auto-Color” Exploited in Live SAP NetWeaver Attack

Kirsten DoyleBy Kirsten DoyleJuly 30, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Malware Auto-Color
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A newly documented attack on a US-based chemicals company is raising fresh concerns in the cybersecurity community, after researchers observed the first-known use of the evasive Auto-Color backdoor malware in conjunction with a critical SAP NetWeaver vulnerability, CVE-2025-31324.

Discovered and contained by Darktrace, the incident involved a multi-stage attack where threat actors used the SAP vulnerability as an entry point to deploy the Auto-Color malware on Linux systems. The backdoor then attempted to persist by hijacking system processes,  but was thwarted by AI-driven detection and autonomous response.

“This is a wake-up call for every organization running SAP,” said Jonathan Stross, SAP Security Analyst at Pathlock. “Darktrace’s detailed research highlights how creatively and effectively attackers can leverage known vulnerabilities to advance along the cyber kill chain.”

A Sophisticated, Stealthy Backdoor

Auto-Color is a Remote Access Trojan (RAT) that first surfaced in November 2024. Named for its tactic of renaming itself to /var/log/cross/auto-color, it has mainly been seen targeting universities and government institutions across North America and Asia.

This latest case is a concerning escalation, as the malware is now being deployed against critical infrastructure.

Researchers found that once deployed, Auto-Color modifies the ld.so.preload configuration on Linux to load a fake library (libcext.so.2) ahead of legitimate ones, allowing it to hijack system calls and evade detection. 

Jason Soroko, Senior Fellow at Sectigo, warned that this technique allows attackers to gain deep system control while remaining virtually invisible.

“The exploit requires no authentication and lets attackers upload helper scripts that pull an ELF payload which renames itself to /var/log/cross/auto-color and persists by adding a fake library called libcext.so.2 to ld.so.preload,” he explained. “Because Auto Color stays largely dormant until it can reach its command server, the initial intrusion creates almost no noise yet grants full host control and a foothold for lateral movement and data theft.” 

CVE-2025-31324: A Persistent Threat

CVE-2025-31324 is a critical vulnerability (CVSS 10.0) in SAP NetWeaver’s Visual Composer Metadata Uploader. Despite patches being available since early 2025, it continues to be actively exploited in the wild.

According to Stross, this demonstrates why SAP security must not remain siloed.

“Traditional SAP Basis teams often lack the experience dealing with remote access trojans (RATs), which are more familiar territory for general IT and cybersecurity teams,” he noted. “Addressing threats, like Auto-Color backdoor malware, requires cross-departmental collaboration. SAP teams, IT operations, and security must work together, share expertise, and ensure SAP systems are not treated as siloed assets.” 

A Wake-Up Call for Critical Infrastructure

Frankie Sclafani, Director of Cybersecurity Enablement at Deepwatch, said the convergence of a critical SAP vulnerability with the elusive Auto-Color malware to target critical infrastructure “signals a disturbing new chapter in cyber threats.” 

“Darktrace’s thorough analysis and findings reveal the first documented case of threat actors exploiting the critical SAP NetWeaver vulnerability (CVE-2025-31324) to deploy Auto-Color backdoor malware,” he added. “To counter these increasingly sophisticated and stealthy multi-stage attacks, organizations must urgently transcend conventional security paradigms and adopt AI-driven, behavioral detection, and autonomous response capabilities.”

Guidance for Security Teams

Experts agree that urgent action is needed. Soroko advised entities running SAP NetWeaver to patch immediately, disable the vulnerable endpoint (/developmentserver/metadatauploader), and restrict inbound and outbound traffic to block Auto-Color’s communication with its operators. 

He also recommended proactive hunting for signs of compromise, including:

  • The presence of helper.jsp or config.sh 
  • Unexpected ZIP uploads 
  • Modifications to /etc/ld.so.preload 
  • Creation of files like libcext.so.2 or auto-color 
  • Outbound traffic over ports 443 or 3232 to unknown IPs

“Prepare containment playbooks that include host isolation, credential rotation and rapid rebuild of affected systems and add network detection rules for these indicators so the organization can prove it has closed exposure,” Soroko added. 

Deep Technical Countermeasures

Mayuresh Dani, Security Research Manager at Qualys Threat Research Unit, urged defenders to look at both sides of the threat: the vulnerability and the malware.

For CVE-2025-31324, he recommended:

  • Immediate patching as per SAP Security Note 3604119 
  • Disabling the Metadata Uploader or blocking it from internet exposure if patching isn’t possible 
  • Adopting a zero-trust architecture

For Auto-Color, Dani advised: 

  • Implementing SELinux policies to prevent modifications to /etc/ld.so.preload 
  • Deploying file integrity monitoring (FIM) for system-critical paths 
  • Enforcing least privilege access and kernel hardening 
  • Using AppArmor or SELinux to restrict unauthorized system changes

What This Attack Means for the Industry

This real-world case underscores several pressing lessons: 

  • SAP systems are high-value targets. Their critical role in business operations makes them attractive to attackers. 
  • Evasion tactics are evolving. Auto-Color can now suppress its activity if it fails to connect to its C2 infrastructure, effectively “pretending to be asleep” to avoid sandbox detection. 
  • Multi-stage attacks are the new normal. A single vulnerability leads to lateral movement, persistence, and exfiltration, making response plans more complex. 
  • Legacy vulnerabilities remain dangerous. Despite disclosures and patches, exploitation continues due to gaps in visibility, governance, or patching processes.

A Warning Shot

“This isn’t just another Linux backdoor,” said Sclafani. “It’s a warning shot, and one the security community must take seriously.”

Darktrace’s research reveals a sharp escalation in adversary capability and intent, combining advanced evasion with critical SAP vulnerabilities to penetrate enterprise networks. As attacks like these become more sophisticated, security teams must evolve faster across departments, technologies, and mindsets. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

When PUPs bite: Huntress uncovers “weaponised” adware exposing 25,000+ systems

April 16, 20262 Mins Read

Fake Tech Support Scams Deliver Advanced Command-and-Control Malware

March 5, 20262 Mins Read

Americans Lost Over $20 million in ATM “Jackpotting” Attacks

February 24, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}