• News/
  • https://www.theregister.com/2025/07/16/sonicwall_vpn_hijack/

Crims hijacking fully patched SonicWall VPNs

The Register
·
Jessica Lyons
·
Published Jul 16, 2025
·
Updated

Updated Unknown miscreants are exploiting fully patched, end-of-life SonicWall VPNs to deploy a previously unknown backdoor and rootkit, likely for data theft and extortion, according to Google's Threat Intelligence Group. In research published on Wednesday, the Chocolate Factory's intel analysts attribute the ongoing campaign to UNC6148 - UNC in Google's threat-actor naming taxonomy stands for "Uncategorized." They appear to be using a backdoor rootkit dubbed OVERSTEP. Once the miscreants compromised the SonicWall appliances, they deployed a previously unknown backdoor written in C. The malware modified the appliance's boot process to maintain persistent access, enabling the criminals to steal sensitive credentials and conceal their own components. The researchers assess "with high confidence" that the criminals are abusing previously stolen credentials and one-time password seeds, which allow them to maintain access to the compromised SonicWall Secure Mobile Access (SMA) 100 series appliances even after organizations have patched the buggy VPNs. Mandiant, Google's incident response arm, investigated one of the intrusions connected with this UNC6148 campaign, and determined that in June the crew established an SSL-VPN session on the SonicWall gear using local administrator credentials. "Mandiant's first observations of UNC6148 in a recent investigation showed that they already had local administrator credentials to the targeted SMA 100 series appliance, and no forensic evide...

Read full article

Affected Software

1 affected component
SonicWall Secure Mobile Access=100

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of fully patched SonicWall VPNs by criminals deploying a backdoor and rootkit.

2

What security implications are discussed?

The article highlights data theft and extortion risks associated with the exploitation of SonicWall VPNs.

3

What products or software are affected?

The affected software mentioned in the article is SonicWall Secure Mobile Access.

4

Who reported the findings regarding the exploitation?

The findings were reported by Google's Threat Intelligence Group.

5

What recent vulnerability is mentioned in relation to SonicWall VPNs?

The article mentions a zero-day vulnerability being exploited in the SonicWall VPNs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203