SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
ID: 48e3cd38-196b-56d3-8db5-90082ff04006
STIX ID: report--48e3cd38-196b-56d3-8db5-90082ff04006
Feed Name: Bleeping Computer
Google Threat Intelligence Group (GTIG) observed UNC6148 deploying a previously unseen user-mode rootkit/backdoor named OVERSTEP against end-of-life SonicWall SMA 100 appliances; the rootkit provides persistent reverse-shell access, anti-forensics, and credential/file theft capabilities. Investigators found evidence of stolen administrator credentials likely obtained via multiple n-day vulnerabilities (and possibly an unknown zero-day), and GTIG links the actor to data theft and potential deployment of Abyss ransomware, providing indicators of compromise and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
