Crims hijacking fully patched SonicWall VPNs to deploy stealthy backdoor and rootkit
ID: d2ffe7d9-859c-53eb-ba3a-e1bdb9f8b45b
STIX ID: report--d2ffe7d9-859c-53eb-ba3a-e1bdb9f8b45b
Feed Name: The Register (Security)
Threat Score
Google Threat Intelligence Group attributes an active campaign (UNC6148) exploiting SonicWall SMA 100 appliances to deploy OVERSTEP, a previously unknown C-written backdoor and rootkit that modifies boot behavior for persistence, removes logs, and steals credentials, certificates and OTPs; investigators observed exploitation via known CVEs and possibly a zero-day, and assess the actors focus on data theft and extortion with potential for ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
