Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

SonicWall SMA persistence operation

Updated 24.09.2025 16:00
Case score 59
Case score 59 Members 1 Latest activity 24.09.2025 16:00
Members 1 First seen 24.09.2025 16:00 Last seen 24.09.2025 16:00 Updated 24.09.2025 16:00

Overview

UNC6148 is actively targeting **SonicWall SMA** appliances with **OVERSTEP**, a persistent backdoor/user-mode rootkit that keeps access on remote-access systems and hides operator activity. The available evidence points to stolen credentials and one-time password seeds from earlier breaches, and some intrusions may have used an unknown zero-day RCE. SonicWall has issued firmware guidance for **SMA 100 series** devices and detection advice focused on log gaps, unexpected reboots, unexplained admin sessions, and unauthorized configuration changes.

Signals

3 derived
Status
Campaign status Active
Threat context
Actor UNC6148 Malware

Malware context

1 families

Member happenings

1 related
Campaign UNC6148 SonicWall SMA exploitation campaign
Updated 24.09.2025 16:00 Lead Contribution 59
Objective Access Brokerage Campaign Active

The **UNC6148** campaign against **SonicWall SMA** appliances is ongoing and is enabling persistent access on targeted devices. The operation uses **OVERSTEP**, a **persistent backdoor/user-mode rootkit**, to hide activity, steal credentials, and keep footholds. The campaign matters because it appears to abuse stolen credentials and possibly an **unknown zero-day RCE** to compromise enterprise remote-access systems.