UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit
Fully-patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series equipment have been the focus of a threat activity cluster that aims to install the OVERSTEP backdoor.
The Google Threat Intelligence Group (GTIG) has linked the harmful activity, which dates back to at least October 2024, to a hacking squad it monitors under the handle UNC6148. At this point, there are "limited" known casualties.
Even after firms have implemented security upgrades, the tech giant concluded with high confidence that the threat actor is using credentials and one-time password (OTP) seeds that were obtained during earlier attacks to recover access.
According to an examination of network traffic metadata records, UNC6148 may have first stolen these login credentials from the SMA appliance as e...

