A critical vulnerability in SAP's NetWeaver software is being actively exploited by multiple ransomware groups and Chinese-backed hackers. The cyberattacks have drawn comparisons to previous large-scale campaigns such as Salt Typhoon and Volt Typhoon. Russian ransomware groups BianLian and RansomEXX have been identified as key actors in exploiting the NetWeaver flaw. Additionally, China-based threat actors are involved in the attack chain. The situation is escalating as ransomware gangs increasingly deploy Skitnet post-exploitation malware to extend their access and impact. Multiple cybersecurity firms are monitoring these zero-day attacks targeting SAP, one of Europe's leading software providers.
Ransomware gangs increasingly use Skitnet post-exploitation malware https://t.co/HrwxxVjnfF
SAP NetWeaver woes worsen as ransomware gangs join the attack https://t.co/TyMib05iG0
The Russian #ransomware groups BianLian and RansomEXX were tied to exploitations of @SAP's NetWeaver bug. China-based threat groups are also involved in the attack chain. #cybersecurity #infosec #ITsecurity https://t.co/uVu90PETIF