SonicWall Secure Mobile Access Attack
ID: 535ac2b5-0888-5120-9add-e7d8f419e79d
STIX ID: report--535ac2b5-0888-5120-9add-e7d8f419e79d
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
A Google Threat Intelligence Group-identified campaign (attributed to UNC6148 with moderate confidence) is actively exploiting SonicWall SMA100 appliances—using multiple CVEs and likely a zero-day—to install a custom Linux rootkit named OVERSTEP that steals admin credentials and OTPs, persists across updates, manipulates logs, and connects outbound to command-and-control; organizations with affected SMA100 devices should investigate for compromise, rotate credentials, and perform deep forensic analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
