SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
Score: 79/100
5 articles
100.0% coherence
16 hours ago
Activity Timeline
SonicWall SMA Appliances Targeted With New ‘Overst...
SecurityWeek
Jul 16
14:00
Hackers Use Backdoor to Steal Data From SonicWall ...
Data Breach Today UK
Jul 16
14:48
SonicWall SMA devices hacked with OVERSTEP rootkit...
BleepingComputer
Primary Article
Jul 16
15:33
Threat actor targets end-of-life SonicWall SMA 100...
Cybersecurity Dive
Jul 16
15:48
SonicWall customers hit by fresh, ongoing attacks ...
CyberScoop
Jul 16
17:52
Primary Article
BleepingComputer 16 hours ago
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
Ionut Ilascu
July 16, 2025
11:33 AM
0
A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances.
The backdoor is a user-mode rootkit that allows hackers to hide malicious components, maintain persistent access on the device, and steal sensitive credentials.
Researchers at Google Threat Intelligence Group (GTIG) observed the rootkit in attacks that may have relied on “an unknown, zero-day remote code execution vulnerability”.
The threat actor is tracked as UNC6148 and has been operating since at least last October, with an organization being targeted as recently as May.
Because files stolen from the victim were later published on the World Leaks (Hunters International rebrand) data-leak site, GTIG researchers believe that UNC6148 engages in data theft and extortion attacks, and may also...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock Cluster AI
Join ThreatCluster Intelligence to access AI-generated executive, technical, and remediation briefs.
A threat actor that may be financially motivated has been targeting SonicWall appliances with a new piece of malware, Google’s Threat Intelligence Group warned on Wednesday.The threat actor, tracked b...
A financially motivated threat group is attacking organizations using fully patched, end-of-life SonicWall Secure Mobile Access 100 series appliances, Google Threat Intelligence Group said in areportr...
Cybercrime,Fraud Management & Cybercrime,Governance & Risk Management
Hackers Use Backdoor to Steal Data From SonicWall Appliance
Credit Eligible
Get Permission
A cybercrime group used a backdoor in a...
Threat actor targets end-of-life SonicWall SMA 100 appliances in ongoing campaign
The hacker has deployed a backdoor to modify the boot process and has exploited several different vulnerabilities duri...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.