State espionage: how 581 SAP systems became the target of a Chinese campaign

State espionage: how 581 SAP systems became the target of a Chinese campaign

A recent espionage campaign attributed to a Chinese APT group reminds us that SAP systems are now strategic targets for states.

For a long time, ERPs remained on the fringes of cybercriminals’ offensive strategies. The focus was mainly on workstations, servers or network infrastructures. This reality is changing rapidly. SAP, one of the most widely used ERP (Enterprise Resource Planning) systems in the world, allows organizations to manage essential processes such as finance, human resources, purchasing or logistics. These systems, which centralize critical data, have today become favored targets of state-backed espionage groups. The recent campaign attributed to an APT (Advanced Persistent Threat) group, an advanced persistent threat generally associated with actors with significant resources, provides a new illustration of this. According to several cybersecurity researchers, 581 SAP systems exposed on the Internet were compromised. The victims are mainly in the United Kingdom and the United States. They include players in the energy, water and other critical infrastructure sectors. This operation confirms that ERPs are no longer just management tools. They are now strategic targets in intelligence operations.

An ideal target for espionage operations

SAP centralizes a considerable amount of sensitive information. Financial data, human resources, purchasing, suppliers, logistics and even asset management are grouped together. For an APT group, accessing this environment represents a particularly valuable source of intelligence. Attackers can map supply chains, identify strategic partners, and understand the inner workings of an organization. In the case of critical infrastructure operators, this information can also be used to prepare future operations or fuel economic intelligence strategies.

A discreet presence for several months

One of the most worrying aspects of this campaign is its duration. The attackers would have managed to maintain their access for several months thanks to persistent backdoors. These “backdoors” allowed them to re-enter compromised environments, even after certain remediation actions. Such an approach is characteristic of APT groups. Their goal is usually not to immediately disrupt their victims. They favor discretion in order to gather information over the long term and evade detection. The longer attackers remain present in an SAP environment, the more strategic data they accumulate. They also increase their possibilities of compromising other connected systems.

An exhibition that is still too often underestimated

This campaign also highlights a persistent weakness. SAP environments still remain insufficiently integrated into overall cybersecurity strategies. In many organizations, ERPs are primarily considered as business tools whose availability must be preserved. This approach can slow down patching and limit detection of suspicious activity. The complexity of SAP environments also reinforces this difficulty. Multiple components, interfaces and privileged accounts provide more opportunities for attackers to hide their actions.

Protection that can no longer be limited to theoretical vulnerabilities

Quickly correcting known vulnerabilities and correcting flaws in specific codes remain essential. Updating and verifying security-critical configurations is a prerequisite. On the other hand, this campaign shows that these actions alone are no longer enough. Organizations must also be able to identify unusual behavior within their SAP environments. This involves several new axes: monitoring human users, machine users, internal and external interfaces, monitoring superusers. Continuous monitoring allows you to detect a compromise more quickly and limit the persistence of attackers. Artificial intelligence plays its role here, which will detect new patterns not identified in the rules of the past. Integration into cybersecurity processes (Security Operation Center, Vulnerability Operation Center) makes it possible to correlate risks with other behaviors at the network and systems level. Finally, the latest line of defense is the ability to block attacks quickly, preventively, through new techniques for blocking risky actions by requesting multi-factor authentication.

Espionage campaigns targeting SAP are no longer exceptional. In this context, protecting ERPs is no longer just about business continuity, but a real strategic security issue.

Leave a Reply

Your email address will not be published. Required fields are marked *