Executive Summary
In early 2024, a sophisticated threat actor group identified as UNC6148 targeted SonicWall Secure Mobile Access (SMA) appliances with a newly discovered backdoor malware named 'OVERSTEP'. By exploiting unpatched vulnerabilities, attackers gained unauthorized access, deployed persistent hidden software, exfiltrated credentials, and established remote control over affected devices. The compromise allowed lateral movement within victim networks, providing attackers with ongoing access to sensitive data and resources while evading detection for extended periods. Organizations using SonicWall SMA were particularly at risk of operational disruptions, data breaches, and unauthorized exposure of business-critical systems.
This incident exemplifies the growing trend of supply-chain and edge-device attacks by advanced persistent threats (APTs). The deployment of stealthy backdoors like OVERSTEP signals increased sophistication and automation among threat actors, further pressuring organizations to improve detection, patch management, and east-west segmentation strategies.
Why This Matters Now
This incident highlights the urgent need for rapid vulnerability management and robust segmentation, as APTs continue to exploit critical network infrastructure for covert, long-term access. With attackers increasingly targeting remote access and VPN appliances, the window for exploitation and lateral movement is narrowing—making immediate defensive action and visibility enhancements essential for organizations.
Attack Path Analysis
The attackers initially compromised exposed SonicWall SMA devices, likely exploiting vulnerabilities to gain unauthorized access. They escalated privileges to obtain administrative control and drop persistent implants. With access, they moved laterally within internal systems, potentially seeking sensitive data or additional credentials. The adversaries established command and control through a covert backdoor for sustained, remote access. Stolen information, such as credentials, may have been exfiltrated over encrypted or disguised channels. The operation enabled the group to maintain access, hide their actions, and set up for potential business disruption or continued espionage.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited vulnerabilities in exposed SonicWall SMA appliances to gain initial foothold.
Related CVEs
CVE-2024-38475
CVSS 9.8An unauthenticated path traversal vulnerability in the embedded Apache HTTP Server of SonicWall SMA 100 series appliances allows remote attackers to exfiltrate sensitive files, including SQLite databases containing user credentials and session tokens.
Affected Products:
SonicWall SMA 100 Series – 10.2.1.7-34sv and earlier
Exploit Status:
exploited in the wildReferences:
CVE-2025-32819
CVSS 7.2An authenticated file deletion vulnerability in SonicWall SMA 100 series appliances allows attackers to delete arbitrary files, potentially leading to a reset of administrator credentials to default values.
Affected Products:
SonicWall SMA 100 Series – 10.2.1.7-34sv and earlier
Exploit Status:
exploited in the wildReferences:
CVE-2021-20038
CVSS 9.8A memory corruption vulnerability in SonicWall SMA 100 series appliances allows unauthenticated remote code execution, enabling attackers to execute arbitrary code on the affected device.
Affected Products:
SonicWall SMA 100 Series – 10.2.1.7-34sv and earlier
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Boot or Logon Autostart Execution
OS Credential Dumping
Impair Defenses
Obfuscated Files or Information
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10(1)
CISA ZTMM 2.0 – Continuous Monitoring and Threat Detection
Control ID: Identity and Access Management: Monitoring and Detection
NIS2 Directive – Incident Handling and Response
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
SonicWall VPN compromises threaten encrypted traffic and egress security, exposing customer data and payment systems to APT lateral movement and credential theft.
Health Care / Life Sciences
UNC6148 backdoor attacks on SonicWall devices compromise HIPAA-required encrypted traffic controls, enabling patient data exfiltration through compromised secure connectivity infrastructure.
Government Administration
Advanced persistent threats targeting SonicWall security appliances undermine zero trust segmentation and threat detection capabilities critical for protecting sensitive government networks.
Professional Training
OVERSTEP backdoor exploitation of SonicWall SMA devices compromises secure hybrid connectivity and multicloud visibility controls protecting distributed educational technology infrastructure.
Sources
- Threat Actor Deploys 'OVERSTEP' Backdoor in Ongoing SonicWall SMA Attackshttps://www.darkreading.com/cyberattacks-data-breaches/threat-actor-deploys-overstep-backdoor-in-ongoing-sonicwall-sma-attacksVerified
- Urgent Advisory for Addressing Rootkits and Other Critical Vulnerabilities in SonicWall SMA 100 Series Applianceshttps://www.sonicwall.com/support/notices/urgent-advisory-for-addressing-rootkits-and-other-critical-vulnerabilities-in-sonicwall-sma-100-series-appliances/250730071322160Verified
- Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoorhttps://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoorVerified
- Google finds custom backdoor being installed on SonicWall network deviceshttps://arstechnica.com/security/2025/07/google-finds-custom-backdoor-being-installed-on-sonicwall-network-devices/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Network segmentation, robust east-west controls, and egress policy enforcement would have contained lateral movement, limited remote command and control, and detected suspicious activity, reducing the attack's progression and impact. Zero Trust principles, including microsegmentation, inline IPS, and encrypted traffic controls, directly constrain adversary actions across multiple attack phases.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized inbound access and exploit attempts.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks escalation exploits and malicious payloads.
Control: Zero Trust Segmentation
Mitigation: Prevents unauthorized workload-to-workload communication.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks suspicious outbound C2 traffic.
Control: Encrypted Traffic (HPE)
Mitigation: Secures data in transit and prevents data leakage in cleartext.
Rapid detection of post-compromise anomalies and persistent foothold.
Impact at a Glance
Affected Business Functions
- Remote Access Services
- Network Security Operations
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive credentials, session tokens, and one-time password seeds, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict cloud firewall policies to limit exposure of management interfaces and prevent initial exploit attempts.
- • Deploy inline intrusion prevention and real-time anomaly detection to identify and block privilege escalation and persistent threats like backdoors.
- • Implement zero trust segmentation to contain lateral movement and enforce least-privilege access between workloads.
- • Apply robust egress filtering and encrypted traffic controls to prevent unauthorized outbound C2 and detect data exfiltration attempts.
- • Establish centralized visibility and rapid response processes to detect anomalies and expedite containment of sophisticated adversary actions.



