0-Day RCE Flaw in SonicWall SMA Devices Exploited to Launch OVERSTEP Ransomware

0-Day RCE Flaw in SonicWall SMA Devices Exploited to Launch OVERSTEP Ransomware Google’s Threat Intelligence Group (GTIG) has uncovered a sophisticated cyberattack campaign targeting end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances, where threat actors are exploiting previously stolen credentials and deploying a new rootkit called OVERSTEP. The financially motivated group, tracked as UNC6148, has been operating since at least October 2024 and is suspected of leveraging an u...

Save to Folder

Choose a folder to save this article: