SonicWall SMA 100 Series Devices Fully Patched Against UNC6148 Backdoors and OVERSTEP Rootkit

Published:

spot_img

Cyber Threats Targeting SonicWall SMA 100 Series Devices

Overview of Recent Threat Activity

Recent cybersecurity analysis has uncovered a concerning trend involving fully-patched, end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances. A campaign has emerged that specifically targets these devices, deploying a backdoor known as OVERSTEP. This threat activity cluster has been linked to a hacking group identified as UNC6148, according to findings from the Google Threat Intelligence Group (GTIG).

Background on the Threat Actors

UNC6148’s malicious activities date back to October 2024. Initial assessments from GTIG suggest that the number of compromised organizations is currently limited. However, the threat actors have shown sophisticated tactics, including leveraging stolen credentials and one-time password (OTP) seeds obtained during earlier intrusions. This capability allows them to re-establish access even after organizations have implemented security updates.

Exfiltration Timeline
Network traffic analysis indicates that UNC6148 may have exfiltrated these credentials as early as January 2025. The precise methods employed to gain initial access remain somewhat obscured, as the threat actors have taken steps to eliminate relevant log entries. However, experts believe they may have exploited known vulnerabilities such as CVE-2021-20035, CVE-2021-20038, CVE-2021-20039, CVE-2024-38475, or CVE-2025-32819.

Possible Access Vectors

Although GTIG posits unverified theories regarding the acquisition of administrator credentials—possibly through information-stealing logs or credential marketplaces—no concrete evidence has surfaced to support this idea.

The methods of malware delivery remain unknown, complicating the complete analysis of how UNC6148 breached these systems.

Exploitation Techniques

Once inside, the threat actors establish an SSL-VPN session and create a reverse shell, although this raises questions. Typically, shell access should not be feasible on these appliances due to inherent design limitations. There’s a strong suspicion that a zero-day vulnerability could have made this feasible.

The reverse shell has been observed executing various reconnaissance and file manipulation commands. It allows UNC6148 to import and export configuration files to maintain uninterrupted operations. Notably, these alterations may incorporate newly imposed rules designed to prevent detection by access gateways.

Introducing OVERSTEP

The ultimate aim of these attacks is to deploy the sophisticated malware OVERSTEP. This implant can alter the boot process of the appliance, ensuring the hackers maintain persistent access. It excels in credential theft and can conceal its components, thus evading detection by modifying standard file system functions.

OVERSTEP operates through a user-mode rootkit which utilizes hijacked library functions, such as open and readdir, to obscure its presence. Moreover, it connects to an attacker-controlled server through embedded web requests to receive further instructions.

Key Commands

Two significant commands associated with OVERSTEP include:

  • dobackshell: Initiates a reverse shell connection to a predetermined IP address and port.
  • dopasswords: Compiles a TAR archive from sensitive files and saves it in a location for potential remote download.

Persistence Mechanisms

GTIG indicates that UNC6148 altered a legitimate file, /etc/rc.d/rc.fwboot, to ensure that OVERSTEP loads whenever the appliance restarts. This manipulation facilitates the malware’s ongoing presence within the system. Following deployment, the threat actors systematically delete relevant logs, including httpd.log and http_request.log, to obscure their activities.

Goal of the Attacks

Google’s findings suggest that UNC6148 may have exploited an unknown zero-day vulnerability to deploy OVERSTEP, indicating intentions behind these operations may include data theft, extortion, or even a ransomware deployment.

Notably, some organizations affected by these attacks have been linked to a data leak site operated by the World Leaks extortion group, which has connections to prior ransomware schemes like Hunters International.

Security Implications

This alarming trend emphasizes the need for enhanced vigilance concerning edge network systems often overlooked by traditional security measures, such as Endpoint Detection and Response (EDR) tools. Google recommends organizations secure disk images for forensic purposes to minimize risks posed by rootkit anti-forensic capabilities. Collaborating with SonicWall may be necessary to obtain disk images from the affected appliances.

SonicWall’s Response

Upon being approached for comments regarding these findings, SonicWall affirmed its commitment to addressing these threats. The company stated it has been actively collaborating with GTIG throughout the investigation. SonicWall plans to accelerate the end-of-support date for the SMA 100 series from October 2027 to December 2025, indicating a proactive approach in safeguarding the existing customer base.

In summary, SonicWall is directing customers towards more modern solutions that offer enhanced security, scalability, and user experience—signaling a shift in alignment with industry trends moving away from legacy hardware to more robust, cloud-based architectures.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...