216.73.217.22

Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor

· Published 18/07/2025 07:34 · Modified 18/07/2025 08:26

Export JSON

Essential information

Published
18/07/2025 07:34
Modified
18/07/2025 08:26
Tags
2025-07-18 CVE-2021-20035 CVE-2021-20038 CVE-2021-20039 CVE-2024-38475 CVE-2025-32819 backdoor credential-theft data exfiltration overstep rootkit sma sonicwall vpn
Related entities
6 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 1 others

Description

A financially-motivated threat actor, UNC6148, is targeting fully patched end-of-life 100 series appliances. They are using stolen credentials and OTP seeds from previous intrusions to regain access. The actor has deployed a new persistent /user-mode called , which modifies the appliance's boot process, steals credentials, and conceals itself. UNC6148 may be using an unknown zero-day vulnerability for deployment. The campaign, ongoing since October 2024, aims at data theft, extortion, and possibly ransomware deployment. 's functionality includes establishing reverse shells, exfiltrating passwords, and implementing usermode capabilities. Organizations are advised to rotate all credentials and follow provided recommendations to mitigate the threat.

External references