Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

SonicWall SMA persistence operation

Updated 24.09.2025 16:00
Case score 59
Members 1 First seen 24.09.2025 16:00 Latest activity 24.09.2025 16:00

Overview

UNC6148 is actively targeting **SonicWall SMA** appliances with **OVERSTEP**, a persistent backdoor/user-mode rootkit that keeps access on remote-access systems and hides operator activity. The available evidence points to stolen credentials and one-time password seeds from earlier breaches, and some intrusions may have used an unknown zero-day RCE. SonicWall has issued firmware guidance for **SMA 100 series** devices and detection advice focused on log gaps, unexpected reboots, unexplained admin sessions, and unauthorized configuration changes.
Latest development

SonicWall discloses UNC6148 OVERSTEP activity against SMA 100 appliances

SonicWall released a firmware update for SonicWall Secure Mobile Access (SMA) 100 series appliances to help remove known rootkit malware, while Google Threat Intelligence Group attributed an ongoing campaign against SonicWall SMA to UNC6148 and described deployment of the OVERSTEP backdoor/user-mode rootkit to maintain persistent access, steal credentials, and hide activity. The guidance points customers to version 10.2.2.2-92sv and to look for SMA log gaps or deletions, unexpected reboots, persistent or unexplained admin sessions, and unauthorized configuration changes.

Signals

CVEs/products
Status
Threat context

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Campaign UNC6148 SonicWall SMA exploitation campaign
Updated 24.09.2025 16:00 Lead Contribution 59
Objective Access Brokerage Campaign Active

The **UNC6148** campaign against **SonicWall SMA** appliances is ongoing and is enabling persistent access on targeted devices. The operation uses **OVERSTEP**, a **persistent backdoor/user-mode rootkit**, to hide activity, steal credentials, and keep footholds. The campaign matters because it appears to abuse stolen credentials and possibly an **unknown zero-day RCE** to compromise enterprise remote-access systems.