Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor
Essential information
- Published
- 18/07/2025 07:34
- Modified
- 18/07/2025 08:26
- Tags
- 2025-07-18 CVE-2021-20035 CVE-2021-20038 CVE-2021-20039 CVE-2024-38475 CVE-2025-32819 backdoor credential-theft data exfiltration overstep rootkit sma sonicwall vpn
- Related entities
- 6 vulnerabilities (cve), 4 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 1 others
Description
A financially-motivated threat actor, UNC6148, is targeting fully patched end-of-life SonicWall SMA 100 series appliances. They are using stolen credentials and OTP seeds from previous intrusions to regain access. The actor has deployed a new persistent backdoor/user-mode rootkit called OVERSTEP, which modifies the appliance's boot process, steals credentials, and conceals itself. UNC6148 may be using an unknown zero-day vulnerability for deployment. The campaign, ongoing since October 2024, aims at data theft, extortion, and possibly ransomware deployment. OVERSTEP's functionality includes establishing reverse shells, exfiltrating passwords, and implementing usermode rootkit capabilities. Organizations are advised to rotate all credentials and follow provided recommendations to mitigate the threat.