Cyber Threats Targeting SonicWall SMA 100 Series Devices
Overview of Recent Threat Activity
Recent cybersecurity analysis has uncovered a concerning trend involving fully-patched, end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances. A campaign has emerged that specifically targets these devices, deploying a backdoor known as OVERSTEP. This threat activity cluster has been linked to a hacking group identified as UNC6148, according to findings from the Google Threat Intelligence Group (GTIG).
Background on the Threat Actors
UNC6148’s malicious activities date back to October 2024. Initial assessments from GTIG suggest that the number of compromised organizations is currently limited. However, the threat actors have shown sophisticated tactics, including leveraging stolen credentials and one-time password (OTP) seeds obtained during earlier intrusions. This capability allows them to re-establish access even after organizations have implemented security updates.
Exfiltration Timeline
Network traffic analysis indicates that UNC6148 may have exfiltrated these credentials as early as January 2025. The precise methods employed to gain initial access remain somewhat obscured, as the threat actors have taken steps to eliminate relevant log entries. However, experts believe they may have exploited known vulnerabilities such as CVE-2021-20035, CVE-2021-20038, CVE-2021-20039, CVE-2024-38475, or CVE-2025-32819.
Possible Access Vectors
Although GTIG posits unverified theories regarding the acquisition of administrator credentials—possibly through information-stealing logs or credential marketplaces—no concrete evidence has surfaced to support this idea.
The methods of malware delivery remain unknown, complicating the complete analysis of how UNC6148 breached these systems.
Exploitation Techniques
Once inside, the threat actors establish an SSL-VPN session and create a reverse shell, although this raises questions. Typically, shell access should not be feasible on these appliances due to inherent design limitations. There’s a strong suspicion that a zero-day vulnerability could have made this feasible.
The reverse shell has been observed executing various reconnaissance and file manipulation commands. It allows UNC6148 to import and export configuration files to maintain uninterrupted operations. Notably, these alterations may incorporate newly imposed rules designed to prevent detection by access gateways.
Introducing OVERSTEP
The ultimate aim of these attacks is to deploy the sophisticated malware OVERSTEP. This implant can alter the boot process of the appliance, ensuring the hackers maintain persistent access. It excels in credential theft and can conceal its components, thus evading detection by modifying standard file system functions.
OVERSTEP operates through a user-mode rootkit which utilizes hijacked library functions, such as open and readdir, to obscure its presence. Moreover, it connects to an attacker-controlled server through embedded web requests to receive further instructions.
Key Commands
Two significant commands associated with OVERSTEP include:
- dobackshell: Initiates a reverse shell connection to a predetermined IP address and port.
- dopasswords: Compiles a TAR archive from sensitive files and saves it in a location for potential remote download.
Persistence Mechanisms
GTIG indicates that UNC6148 altered a legitimate file, /etc/rc.d/rc.fwboot, to ensure that OVERSTEP loads whenever the appliance restarts. This manipulation facilitates the malware’s ongoing presence within the system. Following deployment, the threat actors systematically delete relevant logs, including httpd.log and http_request.log, to obscure their activities.
Goal of the Attacks
Google’s findings suggest that UNC6148 may have exploited an unknown zero-day vulnerability to deploy OVERSTEP, indicating intentions behind these operations may include data theft, extortion, or even a ransomware deployment.
Notably, some organizations affected by these attacks have been linked to a data leak site operated by the World Leaks extortion group, which has connections to prior ransomware schemes like Hunters International.
Security Implications
This alarming trend emphasizes the need for enhanced vigilance concerning edge network systems often overlooked by traditional security measures, such as Endpoint Detection and Response (EDR) tools. Google recommends organizations secure disk images for forensic purposes to minimize risks posed by rootkit anti-forensic capabilities. Collaborating with SonicWall may be necessary to obtain disk images from the affected appliances.
SonicWall’s Response
Upon being approached for comments regarding these findings, SonicWall affirmed its commitment to addressing these threats. The company stated it has been actively collaborating with GTIG throughout the investigation. SonicWall plans to accelerate the end-of-support date for the SMA 100 series from October 2027 to December 2025, indicating a proactive approach in safeguarding the existing customer base.
In summary, SonicWall is directing customers towards more modern solutions that offer enhanced security, scalability, and user experience—signaling a shift in alignment with industry trends moving away from legacy hardware to more robust, cloud-based architectures.


