logo

UNC6148 deploys Overstep malware on SonicWall devices, possibly for ransomware operations

ID: 72ee4a2c-27fb-5826-813b-4a3acfe9ca27

STIX ID: report--72ee4a2c-27fb-5826-813b-4a3acfe9ca27

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-07-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Google’s Threat Intelligence Group attributes a campaign to UNC6148 that has deployed OVERSTEP — a sophisticated C-written user-mode rootkit/backdoor — against SonicWall SMA 100 series appliances since at least October 2024; the malware achieves persistent privileged access via /etc/ld.so.preload (locked immutable), injects into the initrd to survive reboots, hides forensic traces, enables remote shells and targeted data collection/exfiltration, and is associated with at least one May–June 2025 data leak and overlaps with prior Abyss/VSOCI activity, with published IoCs and YARA rules to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.