Posted inCybersecurity News
UNC6148 rolls out new rootkit, OVERSTEP, in suspected zero-day campaign against SonicWall Secure Mobile Access 100 series appliances. Leaked data has already surfaced on World Leaks.
A newly discovered malware campaign is targeting legacy SonicWall Secure Mobile Access (SMA) 100 series appliances, deploying a sophisticated user-mode rootkit known as OVERSTEP. The campaign, attributed to the financially motivated threat group UNC6148, has enabled persistent access to enterprise networks, credential theft, and facilitated follow-on extortion activities linked to ransomware operators.









