logo

SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware

ID: 48e3cd38-196b-56d3-8db5-90082ff04006

STIX ID: report--48e3cd38-196b-56d3-8db5-90082ff04006

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-07-16

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Google Threat Intelligence Group (GTIG) observed UNC6148 deploying a previously unseen user-mode rootkit/backdoor named OVERSTEP against end-of-life SonicWall SMA 100 appliances; the rootkit provides persistent reverse-shell access, anti-forensics, and credential/file theft capabilities. Investigators found evidence of stolen administrator credentials likely obtained via multiple n-day vulnerabilities (and possibly an unknown zero-day), and GTIG links the actor to data theft and potential deployment of Abyss ransomware, providing indicators of compromise and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.