logo

Zero-Day Vulnerability Exploited to Deploy Stealthy Overstep Backdoor

ID: 521e1951-f8fe-5a1a-91a3-b7627d2f02f6

STIX ID: report--521e1951-f8fe-5a1a-91a3-b7627d2f02f6

Feed Name: Halcyon Blog

Threat Score
90/100

Date Published: 2025-07-18

Date Updated: 2026-04-28

...
...

Researchers report an active campaign where attackers, likely tied to the Abyss ransomware group, exploit a probable zero-day in SonicWall SMA 100 series devices to gain SSL VPN access using harvested credentials, escalate privileges via a reverse shell, and deploy a stealthy 32-bit ELF user-mode rootkit called Overstep that hooks the dynamic linker and modifies the bootloader for persistent, hard-to-detect access; the campaign leverages prior CVEs and aligns with UNC6148 tactics, posing a high-risk, sophisticated threat to organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.