HomeSecuritySonicWall SMA appliances compromised with OVERSTEP rootkit

SonicWall SMA appliances compromised with OVERSTEP rootkit

A malicious actor has developed a previously unknown rootkit called OVERSTEP, which modifies the boot process of SonicWall Secure Mobile Access (SMA) devices that, while fully updated, are no longer officially supported.

See also: SonicWall: Fake NetExtender steals VPN credentials

SonicWall rootkit OVERSTEP

The rootkit allows attackers to hide malicious elements, maintain permanent access to the device, and steal sensitive credentials.

Researchers at the Google Threat Intelligence Group (GTIG) have identified the rootkit in attacks that likely exploited “an unknown zero-day remote code execution vulnerability.” The threat actor is tracked as UNC6148 and has been active since at least last October, with its most recent target being identified in May.

Because files stolen from victims were later published on the data leak website World Leaks, GTIG researchers believe that UNC6148 is involved in data theft and extortion attacks, and may also be using the Abyss ransomware malware (which GTIG tracks under the name VSOCIETY).

Hackers are targeting SonicWall SMA 100 Series appliances that have reached their end-of-life (EoL) and provide secure remote access to corporate resources either on-premises, in the cloud, or in hybrid datacenters.

See also: SonicWall SMA1000 vulnerability allows remote access

It is unclear how the attackers initially gained access, but researchers analyzing the UNC6148 attacks found that the threat actor already had local administrator credentials on the targeted device. Analysis of network trafficindicated that the credentials had been stolen since January.

SonicWall SMA appliances compromised with OVERSTEP rootkit
SonicWall SMA appliances compromised with OVERSTEP rootkit

They likely exploited one or more known vulnerabilities (n-day vulnerabilities), such as:
CVE-2021-20038, CVE-2024-38475, CVE-2021-20035, CVE-2021-20039 and CVE-2025-32819 — with the oldest being made public in 2021 and the newest in May 2025.

Of these, hackers may have exploited CVE-2024-38475, as it allows the acquisition of “administrator credentials and valid session tokens” which UNC6148 could reuse.

However, incident analysts at Mandiant (a Google company) were unable to confirm whether the specific vulnerability was actually exploited by the attacker.

See also: SonicWall patches three serious vulnerabilities in SMA devices

Based on the above, a worrying pattern emerges in the cybersecurity field : outdated devices that are no longer supported by the manufacturer (such as SonicWall SMA 100 Series in End-of-Life status) are attractive targets for advanced threat actors such as the UNC6148 group.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS