A recently revealed security vulnerability in SAP NetWeaver, tagged as CVE-2025-31324, is reportedly being used by at least two distinct cybercrime organizations, BianLian and RansomExx. This suggests that several threat actors are abusing the vulnerability.
In a new report released today, cybersecurity company ReliaQuest said it has found evidence of involvement from the RansomExx ransomware family, which Microsoft tracks under the name Storm-2460, and the BianLian data extortion crew.
Based on infrastructure ties to IP addresses previously identified as belonging to the e-crime organization, BianLian is evaluated as having been involved in at least one event.
According to the company, we found a server at 184[.]174[.]96[.]74 that was providing reverse proxy services that were started by the rs64.exe executable. The same hosting company runs another IP address, 184[.]174[.]96[.]70, which is connected to this server. The second IP has already been identified as a BianLian-affiliated command-and-control (C2) server read more about BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
