SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware

Score: 79/100 5 articles 100.0% coherence 16 hours ago

Activity Timeline

SonicWall SMA Appliances Targeted With New ‘Overst...
SecurityWeek
Jul 16
14:00
Hackers Use Backdoor to Steal Data From SonicWall ...
Data Breach Today UK
Jul 16
14:48
SonicWall SMA devices hacked with OVERSTEP rootkit...
BleepingComputer
Primary Article
Jul 16
15:33
Threat actor targets end-of-life SonicWall SMA 100...
Cybersecurity Dive
Jul 16
15:48
SonicWall customers hit by fresh, ongoing attacks ...
CyberScoop
Jul 16
17:52
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware Ionut Ilascu July 16, 2025 11:33 AM 0 A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances. The backdoor is a user-mode rootkit that allows hackers to hide malicious components, maintain persistent access on the device, and steal sensitive credentials. Researchers at Google Threat Intelligence Group (GTIG) observed the rootkit in attacks that may have relied on “an unknown, zero-day remote code execution vulnerability”. The threat actor is tracked as UNC6148 and has been operating since at least last October, with an organization being targeted as recently as May. Because files stolen from the victim were later published on the World Leaks (Hunters International rebrand) data-leak site, GTIG researchers believe that UNC6148 engages in data theft and extortion attacks, and may also...

Cluster AI

Beta Organization

Save to Folder

Choose a folder to save this cluster: