Google Threat Intelligence Group reported an ongoing campaign targeting fully patched, end-of-life SonicWall SMA 100 appliances, where suspected financially motivated actor UNC6148 deployed the OVERSTEP backdoor to maintain persistent access, steal credentials, and evade detection by selectively removing log entries and modifying the boot process. The activity appears to date back to at least October 2024 and affected SMA 210, SMA 410, and SMA 500v devices, with the actor reportedly regaining access using previously stolen administrator credentials and OTP seeds; investigators also assessed with moderate confidence that an unknown zero-day remote code execution path may have been used to install the malware and obtain shell access.
Subsequent reporting said SonicWall released updated firmware for SMA 100 appliances that adds advanced file integrity checks to detect and remove known rootkits, after exploitation tied the campaign to CVE-2024-38475 in Apache HTTP Server and CVE-2025-40599 in SonicWall SMA 100. The intrusions enabled reverse shells and theft of sensitive data including persist.database, certificates, credentials, and OTP seeds, and were linked to follow-on extortion and possible ransomware activity, including overlap with incidents associated with Abyss-branded ransomware and a victim later named on the World Leaks site; defenders were urged to apply SonicWall guidance, rotate all credentials, reset MFA tokens, and consider migration as SMA 100 support ended.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK stated that SonicWall urged administrators to consider migration because support for SMA 100 ended on October 1, 2025. This marked the platform's end-of-support status.
CSIRT.SK reported that SonicWall released a firmware update for SMA 100 series appliances that adds advanced file integrity checking to detect and remove known rootkits. The update was described as a response to active exploitation involving UNC6148 and OVERSTEP.
On its July 2025 publication, GTIG disclosed that suspected financially motivated actor UNC6148 was deploying a newly identified persistent backdoor and user-mode rootkit called OVERSTEP on SonicWall SMA 100 appliances. GTIG said the malware modified the boot process, stole credentials, hid its components, and may have been deployed via an unknown zero-day RCE.
GTIG cited a victim from May 2025 that was later posted to the World Leaks leak site in June 2025, indicating the campaign may support data theft and extortion. This linked the activity to downstream public extortion pressure.
Google Threat Intelligence Group assessed that the ongoing campaign targeting fully patched, end-of-life SonicWall SMA 100 series appliances dates back to at least October 2024. The actor was believed to regain access using administrator credentials and OTP seeds stolen in earlier intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecloud.google.com
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.