Chaya_004 is a suspected China-linked threat actor associated with exploitation of SAP NetWeaver Visual Composer vulnerabilities, particularly CVE-2025-31324. The actor has been linked to targeted intrusions against internet-exposed SAP NetWeaver systems and to large-scale backdooring of vulnerable instances, including organizations in critical infrastructure environments. Reported victim geography includes the United Kingdom, the United States, and Saudi Arabia. The actor’s operations have involved initial access through exploitation of unauthenticated remote code execution or arbitrary file upload conditions in SAP NetWeaver, followed by deployment of web shells and backdoors including SuperShell. Activity attributed to Chaya_004 also includes use of attacker-controlled infrastructure hosted on Chinese cloud providers and use of multiple penetration-testing tools. The reported objective appears to be establishing persistent access on compromised enterprise application servers that can enable follow-on post-exploitation activity. Compromised SAP environments are especially valuable because of their deep integration with business processes and, in some cases, industrial and operational networks. Chaya_004’s intrusions therefore present elevated risk of persistence, internal reconnaissance, lateral movement, service disruption, and potential intelligence collection. Available reporting supports assessment of a China nexus and an espionage-oriented strategic context, but does not establish publicly known sub-groups or widely used alternative aliases beyond Chaya_004.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked intrusion activity exploiting SAP NetWeaver RCE (CVE-2025-31324) and deploying Golang-based tooling (SuperShell).
Chaya_004 is a Chinese APT group reported to be actively exploiting SAP NetWeaver CVE-2025-31324, targeting critical infrastructure and enterprise systems.
Targeting SAP NetWeaver vulnerabilities for cyber-espionage, likely as part of broader Chinese APT activity.
Suspected China-linked activity cluster exploiting SAP NetWeaver (CVE-2025-31324) using infrastructure hosting Supershell backdoors and various pentesting tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.