BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan

Source: The Hacker News
Published: 2025-05-14 17:50
Fetched: 2025-05-14 18:17

Summary

Cybercriminal groups BianLian and RansomExx have been found exploiting a newly disclosed vulnerability in SAP NetWeaver to deploy the PipeMagic Trojan, highlighting the ongoing risks associated with unpatched software. According to cybersecurity firm ReliaQuest, these groups are leveraging the flaw to engage in data extortion and ransomware activities. This incident underscores the importance of timely patch management and vigilance in monitoring for unusual activities within enterprise systems. The exploitation of this SAP NetWeaver flaw by multiple threat actors signals a broader trend of cybercriminals targeting widely used enterprise software. Organizations using SAP NetWeaver should prioritize patching this vulnerability to mitigate potential breaches and data loss.

LinkedIn Post

Cybercrime groups BianLian & RansomExx exploit SAP NetWeaver flaw to deploy PipeMagic Trojan, stressing the need for prompt patching. Stay vigilant & protect your enterprise systems. #CyberSecurity #SAPNetWeaver #DataProtection #Ransomware #PatchManagement https://thehackernews.com/2025/05/bianlian-and-ransomexx-exploit-sap.html

Content

At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver, indicating that multiple threat actors are taking advantage of the bug. Cybersecurity firm ReliaQuest, in a new update published today, said it uncovered evidence suggesting involvement from the BianLian data extortion crew and the RansomExx ransomware