SonicWall has issued firmware version 10.2.2.2-92sv for SMA 100 series devices, enabling removal of the OVERSTEP rootkit deployed by threat group UNC6148. The update addresses exploitation via CVE-2024-38475 and includes additional file-checking capabilities. Organizations are urged to upgrade, rotate credentials, and consider migrating to supported hardware as end-of-support for SMA 100 series is accelerated to December 31, 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SonicWall's SMA 100 series appliances were scheduled to reach end-of-support, increasing urgency for customers to upgrade or replace affected devices amid the ongoing UNC6148 campaign.
The Canadian Centre for Cyber Security published advisory AV25-612 covering the SonicWall security issue, reflecting government awareness and dissemination of mitigation guidance related to the SMA threat activity and remediation.
In a separate advisory referenced alongside the SMA campaign, SonicWall said a malicious actor used brute-force techniques against the MySonicWall.com portal and accessed firewall configuration or customer information tied to its cloud backup service. SonicWall said the incident affected fewer than 5% of its firewall installed base.
SonicWall released firmware version 10.2.2.2-92sv for SMA 210, 410, and 500v appliances, adding file-checking and rootkit-removal capabilities aimed at detecting and wiping known OVERSTEP malware. The company urged customers to upgrade immediately and follow additional remediation guidance.
Google Threat Intelligence Group reported an ongoing campaign in which threat actor UNC6148 targeted SonicWall SMA 100 series appliances, including fully patched end-of-life devices, deploying the previously unknown OVERSTEP backdoor/rootkit for persistence, credential theft, and evasion. GTIG said the actor may have used stolen credentials and OTP seeds from prior breaches and possibly an unknown zero-day remote code execution flaw.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.