logo

Fully Patched SonicWall Gear Under Likely Zero-Day Attack

ID: e810dc8d-5c20-5b1e-a2b9-c583f097d465

STIX ID: report--e810dc8d-5c20-5b1e-a2b9-c583f097d465

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-07-16

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

GTIG observed an active campaign (UNC6148) compromising SonicWall SMA 100 series devices — likely using stolen local admin credentials and one or more unpatched vulnerabilities — to install a novel persistent user-mode rootkit/backdoor called Overstep. The backdoor modifies the appliance boot process to maintain persistence, hide components, and exfiltrate credentials; activity is linked to the Abyss ransomware cluster and may have been ongoing since October 2024. Organizations with affected devices are advised to perform forensic disk analysis, hunt for compromises, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.