logo

SonicWall Secure Mobile Access Attack

ID: 535ac2b5-0888-5120-9add-e7d8f419e79d

STIX ID: report--535ac2b5-0888-5120-9add-e7d8f419e79d

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
78/100

Date Published: 2025-07-18

Date Updated: 2026-07-28

...
...

A Google Threat Intelligence Group-identified campaign (attributed to UNC6148 with moderate confidence) is actively exploiting SonicWall SMA100 appliances—using multiple CVEs and likely a zero-day—to install a custom Linux rootkit named OVERSTEP that steals admin credentials and OTPs, persists across updates, manipulates logs, and connects outbound to command-and-control; organizations with affected SMA100 devices should investigate for compromise, rotate credentials, and perform deep forensic analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.