The Containment Era is here. →Explore

Executive Summary

In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations.

The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.

Why This Matters Now

Legacy and end-of-life network security appliances are increasingly targeted with advanced rootkits and ransomware toolkits, enabling persistent access and credential theft. As support windows close, unpatched vulnerabilities and aging firmware represent urgent liabilities—highlighting the need for proactive upgrade strategies and zero trust segmentation to mitigate modern threat actor techniques.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers exploited vulnerabilities in legacy SMA100 firmware, deploying the OVERSTEP rootkit to maintain persistent, unauthorized access and extract sensitive information.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust Segmentation, egress policy enforcement, inline threat detection, and east-west traffic controls would have limited the attacker's ability to initially compromise legacy devices, pivot within the environment, establish C2, and exfiltrate sensitive data. CNSF-aligned controls mapped to each kill chain phase ensure visibility, rapid detection, and prevention of similar advanced persistent threat and ransomware operations.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Exploitable external attack surface is minimized, and known malicious payloads are blocked.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Lateral movement with stolen credentials is hampered by strict identity-based access policies.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unauthorized lateral flows are detected or automatically blocked.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known C2 signatures and anomalous remote access activity are detected and blocked.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts to unauthorized destinations are blocked, and abnormal flows are flagged.

Impact (Mitigations)

Anomalous encryption activity and unauthorized backup access trigger alerts and response protocols.

Impact at a Glance

Affected Business Functions

  • Remote Access
  • Network Security
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive credentials, OTP seeds, and certificates, leading to unauthorized access and data breaches.

Recommended Actions

  • Enforce strict Zero Trust Segmentation to isolate vulnerable infrastructure and limit identity-based lateral movement.
  • Deploy advanced Cloud Firewall and Inline IPS at all internet-facing and internal segments to detect and block exploit attempts and C2 traffic.
  • Implement East-West Traffic Security and Egress Policy Enforcement to prevent lateral movement and block unauthorized data exfiltration from sensitive workloads.
  • Continuously monitor for threats using real-time anomaly response tools that baseline normal device and user behaviors and rapidly isolate compromised assets.
  • Regularly update and patch all VPNs, firewalls, and legacy appliances, and ensure comprehensive visibility into all cloud and hybrid assets with centralized CNSF controls.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image