• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-sma-devices-hacked-with-overstep-rootkit-tied-to-ransomware/

SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware

BleepingComputer
·
Ionut Ilascu
·
Published Jul 16, 2025
·
Updated

A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances. The backdoor is a user-mode rootkit that allows hackers to hide malicious components, maintain persistent access on the device, and steal sensitive credentials. Researchers at Google Threat Intelligence Group (GTIG) observed the rootkit in attacks that may have relied on “an unknown, zero-day remote code execution vulnerability”. The threat actor is tracked as UNC6148 and has been operating since at least last October, with an organization being targeted as recently as May. Because files stolen from the victim were later published on the World Leaks (Hunters International rebrand) data-leak site, GTIG researchers believe that UNC6148 engages in data theft and extortion attacks, and may also deploy Abyss ransomware (tracked as  VSOCIETY by GTIG). The hackers are targeting end-of-life (EoL) SonicWall SMA 100 Series devices that provide secure remote access to enterprise resources on the local network, in the cloud, or hybrid datacenters. It is unclear how the hackers obtained initial access, but researchers investigating UNC6148 attacks noticed that the threat actor already had local administrator credentials on the targeted appliance. “GTIG assesses with high confidence that UNC6148 exploited a known vulnerability to steal administrator credentials prior to the targeted SMA appliance be...

Read full article

Affected Software

1 affected component
SonicWall Secure Mobile Access

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the hacking of SonicWall Secure Mobile Access devices using a new malware called OVERSTEP.

2

What security implications are discussed?

The security implications include the exploitation of unsupported devices, potentially leading to unauthorized access and data breaches.

3

What products or software are affected?

The affected product is the SonicWall Secure Mobile Access appliance.

4

Who is responsible for the OVERSTEP rootkit attacks?

The article suggests that a threat actor is responsible for deploying the OVERSTEP rootkit.

5

Is the SonicWall Secure Mobile Access still supported?

No, the devices are fully patched but no longer supported by SonicWall.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203