Auto-Color is a stealthy Linux backdoor observed in attacks exploiting the SAP NetWeaver zero-day vulnerability CVE-2025-31324. Publicly available information directly supports its use as a post-compromise payload delivered through exploitation of exposed SAP NetWeaver systems. High-confidence reporting in the available material identifies Auto-Color as malware rather than a named intrusion set, and does not establish a distinct threat actor identity, origin country, organizational affiliation, victimology beyond the SAP NetWeaver intrusion vector, or broader campaign history. Based on the confirmed facts, Auto-Color should be understood as a Linux backdoor associated with initial access via exploitation of a critical enterprise software vulnerability and subsequent post-exploitation activity on compromised hosts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.