logo

Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor

ID: f9cb8ae3-baf8-53e5-a0d1-7b9e88f5a2fa

STIX ID: report--f9cb8ae3-baf8-53e5-a0d1-7b9e88f5a2fa

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-07-16

Date Updated: 2026-04-27

Author: Mandiant

...
...

Google Threat Intelligence Group and Mandiant report that UNC6148, a financially motivated actor, has been compromising SonicWall SMA 100 series appliances since at least late 2024 by leveraging stolen credentials and multiple vulnerabilities (and possibly a zero-day). The actor deploys a novel persistent user-mode rootkit named OVERSTEP that modifies the boot process, steals credentials (including OTP seeds), hides components, and enables ongoing access for data theft and extortion; at least one victim's data was posted to a leak site and activity overlaps with prior Abyss/VSOCIETY ransomware intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.