Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor
ID: f9cb8ae3-baf8-53e5-a0d1-7b9e88f5a2fa
STIX ID: report--f9cb8ae3-baf8-53e5-a0d1-7b9e88f5a2fa
Feed Name: Threat Intelligence
Google Threat Intelligence Group and Mandiant report that UNC6148, a financially motivated actor, has been compromising SonicWall SMA 100 series appliances since at least late 2024 by leveraging stolen credentials and multiple vulnerabilities (and possibly a zero-day). The actor deploys a novel persistent user-mode rootkit named OVERSTEP that modifies the boot process, steals credentials (including OTP seeds), hides components, and enables ongoing access for data theft and extortion; at least one victim's data was posted to a leak site and activity overlaps with prior Abyss/VSOCIETY ransomware intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
