logo

Crims hijacking fully patched SonicWall VPNs to deploy stealthy backdoor and rootkit

ID: d2ffe7d9-859c-53eb-ba3a-e1bdb9f8b45b

STIX ID: report--d2ffe7d9-859c-53eb-ba3a-e1bdb9f8b45b

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-07-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Google Threat Intelligence Group attributes an active campaign (UNC6148) exploiting SonicWall SMA 100 appliances to deploy OVERSTEP, a previously unknown C-written backdoor and rootkit that modifies boot behavior for persistence, removes logs, and steals credentials, certificates and OTPs; investigators observed exploitation via known CVEs and possibly a zero-day, and assess the actors focus on data theft and extortion with potential for ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.