SonicWall SMA persistence operation
Case score 59
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 59
- Main story score
- 59
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign Lead campaign against SonicWall SMA appliances using OVERSTEP for persistence and concealment. main
Overview
SonicWall discloses UNC6148 OVERSTEP activity against SMA 100 appliances
SonicWall released a firmware update for SonicWall Secure Mobile Access (SMA) 100 series appliances to help remove known rootkit malware, while Google Threat Intelligence Group attributed an ongoing campaign against SonicWall SMA to UNC6148 and described deployment of the OVERSTEP backdoor/user-mode rootkit to maintain persistent access, steal credentials, and hide activity. The guidance points customers to version 10.2.2.2-92sv and to look for SMA log gaps or deletions, unexpected reboots, persistent or unexplained admin sessions, and unauthorized configuration changes.