Executive Summary
In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations.
The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.
Why This Matters Now
Legacy and end-of-life network security appliances are increasingly targeted with advanced rootkits and ransomware toolkits, enabling persistent access and credential theft. As support windows close, unpatched vulnerabilities and aging firmware represent urgent liabilities—highlighting the need for proactive upgrade strategies and zero trust segmentation to mitigate modern threat actor techniques.
Attack Path Analysis
Attackers exploited a vulnerability in unpatched SonicWall SMA100 devices to gain initial access, deploying rootkit malware and web shells. They escalated privileges by stealing sensitive files, including credential stores and certificate files, to deepen persistence. The attackers leveraged compromised devices and their network position to move laterally within the environment. Through the established reverse shell and concealed malware, they maintained command and control. Sensitive data, such as persistent databases and possibly backup configs, was exfiltrated using outbound channels. Finally, ransomware impacts were enabled through persistence, data exfiltration, and possible disruption or encryption of systems and backups.
Kill Chain Progression
Initial Compromise
Description
UNC6148 exploited an unpatched or end-of-life SonicWall SMA100 device vulnerability (e.g., CVE-2024-40766) to deliver rootkit malware and web shells.
Related CVEs
CVE-2024-38475
CVSS 9.8A path traversal vulnerability in SonicWall SMA 100 series devices allows unauthorized access to sensitive session files, enabling session hijacking.
Affected Products:
SonicWall SMA 100 Series – ≤ 10.2.1.14-75sv
Exploit Status:
exploited in the wildCVE-2025-40599
CVSS 9.1An authenticated arbitrary file upload vulnerability in SonicWall SMA 100 series devices allows attackers to upload malicious files, potentially leading to remote code execution.
Affected Products:
SonicWall SMA 100 Series – ≤ 10.2.1.15-81sv
Exploit Status:
no public exploitCVE-2024-40766
CVSS 9.8An improper access control vulnerability in SonicWall SonicOS management access allows unauthorized resource access and can cause the firewall to crash.
Affected Products:
SonicWall SonicOS – ≤ 7.0.1-5035
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise
Create Account
Boot or Logon Autostart Execution: Trap installation
Impair Defenses: Disable or Modify Tools
Obfuscated Files or Information
Valid Accounts
OS Credential Dumping
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Vulnerability and Patch Management
Control ID: Asset Management: Patch/Configuration Management
NIS2 Directive – Cybersecurity Risk-management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
SonicWall SMA100 rootkit compromises directly impact security providers using these devices, enabling persistent access and credential theft affecting client protection capabilities.
Financial Services
OVERSTEP malware targeting SMA100 devices threatens financial institutions' VPN infrastructure, potentially exposing sensitive customer data and violating compliance requirements like PCI-DSS.
Health Care / Life Sciences
Healthcare organizations using vulnerable SMA100 appliances face ransomware exposure through UNC6148 attacks, risking patient data breaches and HIPAA compliance violations.
Government Administration
Government agencies with end-of-life SMA100 devices are vulnerable to persistent rootkit attacks enabling credential harvesting and potential nation-state surveillance activities.
Sources
- SonicWall releases SMA100 firmware update to wipe rootkit malwarehttps://www.bleepingcomputer.com/news/security/sonicwall-releases-sma100-firmware-update-to-wipe-rootkit-malware/Verified
- Urgent Advisory for Addressing Rootkits and Other Critical Vulnerabilities in SonicWall SMA 100 Series Applianceshttps://www.sonicwall.com/support/notices/urgent-advisory-for-addressing-rootkits-and-other-critical-vulnerabilities-in-sonicwall-sma-100-series-appliances/250730071322160Verified
- CVE-2024-40766 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2024-40766Verified
- Ongoing active exploitation of SonicWall SSL VPNs in Australia (CVE-2024-40766)https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australiaVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust Segmentation, egress policy enforcement, inline threat detection, and east-west traffic controls would have limited the attacker's ability to initially compromise legacy devices, pivot within the environment, establish C2, and exfiltrate sensitive data. CNSF-aligned controls mapped to each kill chain phase ensure visibility, rapid detection, and prevention of similar advanced persistent threat and ransomware operations.
Control: Cloud Firewall (ACF)
Mitigation: Exploitable external attack surface is minimized, and known malicious payloads are blocked.
Control: Zero Trust Segmentation
Mitigation: Lateral movement with stolen credentials is hampered by strict identity-based access policies.
Control: East-West Traffic Security
Mitigation: Unauthorized lateral flows are detected or automatically blocked.
Control: Inline IPS (Suricata)
Mitigation: Known C2 signatures and anomalous remote access activity are detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts to unauthorized destinations are blocked, and abnormal flows are flagged.
Anomalous encryption activity and unauthorized backup access trigger alerts and response protocols.
Impact at a Glance
Affected Business Functions
- Remote Access
- Network Security
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive credentials, OTP seeds, and certificates, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict Zero Trust Segmentation to isolate vulnerable infrastructure and limit identity-based lateral movement.
- • Deploy advanced Cloud Firewall and Inline IPS at all internet-facing and internal segments to detect and block exploit attempts and C2 traffic.
- • Implement East-West Traffic Security and Egress Policy Enforcement to prevent lateral movement and block unauthorized data exfiltration from sensitive workloads.
- • Continuously monitor for threats using real-time anomaly response tools that baseline normal device and user behaviors and rapidly isolate compromised assets.
- • Regularly update and patch all VPNs, firewalls, and legacy appliances, and ensure comprehensive visibility into all cloud and hybrid assets with centralized CNSF controls.



