Zero-Day Vulnerability Exploited to Deploy Stealthy Overstep Backdoor
ID: 521e1951-f8fe-5a1a-91a3-b7627d2f02f6
STIX ID: report--521e1951-f8fe-5a1a-91a3-b7627d2f02f6
Feed Name: Halcyon Blog
Researchers report an active campaign where attackers, likely tied to the Abyss ransomware group, exploit a probable zero-day in SonicWall SMA 100 series devices to gain SSL VPN access using harvested credentials, escalate privileges via a reverse shell, and deploy a stealthy 32-bit ELF user-mode rootkit called Overstep that hooks the dynamic linker and modifies the bootloader for persistent, hard-to-detect access; the campaign leverages prior CVEs and aligns with UNC6148 tactics, posing a high-risk, sophisticated threat to organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
