Fully Patched SonicWall Gear Under Likely Zero-Day Attack
ID: e810dc8d-5c20-5b1e-a2b9-c583f097d465
STIX ID: report--e810dc8d-5c20-5b1e-a2b9-c583f097d465
Feed Name: Dark Reading
GTIG observed an active campaign (UNC6148) compromising SonicWall SMA 100 series devices — likely using stolen local admin credentials and one or more unpatched vulnerabilities — to install a novel persistent user-mode rootkit/backdoor called Overstep. The backdoor modifies the appliance boot process to maintain persistence, hide components, and exfiltrate credentials; activity is linked to the Abyss ransomware cluster and may have been ongoing since October 2024. Organizations with affected devices are advised to perform forensic disk analysis, hunt for compromises, and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
