Updated Unknown miscreants are exploiting fully patched, end-of-life SonicWall VPNs to deploy a previously unknown backdoor and rootkit, likely for data theft and extortion, according to Google's Threat Intelligence Group. In research published on Wednesday, the Chocolate Factory's intel analysts attribute the ongoing campaign to UNC6148 - UNC in Google's threat-actor naming taxonomy stands for "Uncategorized." They appear to be using a backdoor rootkit dubbed OVERSTEP. Once the miscreants compromised the SonicWall appliances, they deployed a previously unknown backdoor written in C. The malware modified the appliance's boot process to maintain persistent access, enabling the criminals to steal sensitive credentials and conceal their own components. The researchers assess "with high confidence" that the criminals are abusing previously stolen credentials and one-time password seeds, which allow them to maintain access to the compromised SonicWall Secure Mobile Access (SMA) 100 series appliances even after organizations have patched the buggy VPNs. Mandiant, Google's incident response arm, investigated one of the intrusions connected with this UNC6148 campaign, and determined that in June the crew established an SSL-VPN session on the SonicWall gear using local administrator credentials. "Mandiant's first observations of UNC6148 in a recent investigation showed that they already had local administrator credentials to the targeted SMA 100 series appliance, and no forensic evide...
Crims hijacking fully patched SonicWall VPNs
The Register
·Jessica Lyons
·Published Jul 16, 2025
·Updated
Affected Software
1 affected component
SonicWall Secure Mobile Access=100
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of fully patched SonicWall VPNs by criminals deploying a backdoor and rootkit.
2
What security implications are discussed?
The article highlights data theft and extortion risks associated with the exploitation of SonicWall VPNs.
3
What products or software are affected?
The affected software mentioned in the article is SonicWall Secure Mobile Access.
4
Who reported the findings regarding the exploitation?
The findings were reported by Google's Threat Intelligence Group.
5
What recent vulnerability is mentioned in relation to SonicWall VPNs?
The article mentions a zero-day vulnerability being exploited in the SonicWall VPNs.