SonicWall Under Siege: Hackers Exploit Patched Devices with Undetectable Rootkit

Listen to this Post

Featured Image

The Silent Cyber Storm Brewing Behind Fully Patched Firewalls

In a startling development, cybercrime researchers from

Hackers Defy Patches with Stealthy Rootkit in SonicWall Attacks

UNC6148, a cybercrime group with apparent financial motives, is actively exploiting end-of-life SonicWall SMA 100 series appliances, despite those devices being fully patched. According to coordinated research by Mandiant and Google’s GTIG, these hackers are bypassing security by using stolen credentials and one-time password (OTP) seeds collected during earlier compromises. These credentials allow them to deploy a new malware strain dubbed “OVERSTEP”, which remains persistent even after updates are applied. Analysts suspect that the group gained initial access using either known or possibly unknown remote code execution vulnerabilities, though evidence is sparse due to the attackers’ use of advanced anti-forensic tools.

OVERSTEP is designed as a stealthy, persistent Linux rootkit that alters the device’s boot process by injecting malicious code into startup scripts and preload configurations. This enables the malware to hide files, processes, and itself from system inspections, and to create covert reverse shells for ongoing access. It also steals credentials, session tokens, and encryption keys by hijacking access to sensitive files.

Incident responders observed that OVERSTEP deletes shell history and log entries, frustrating attempts at forensic investigation. The campaign seems to have begun in late 2024 and overlaps with other attacks involving the Abyss/VSOCIETY ransomware group. One victim’s data was later found on the “World Leaks” extortion site, suggesting the attacks may be part of broader ransomware operations.

Despite applying all official patches, affected organizations are finding that UNC6148 maintains access using credentials harvested from earlier attacks. As a result, defenders are being urged to rotate all keys, reset all credentials, and replace SSL/TLS certificates. Investigators also recommend imaging devices for offline analysis, watching for unusual files, modified boot configurations, and traffic to known command-and-control infrastructure.

The campaign demonstrates the high risk of relying on unsupported perimeter hardware, even when patched. The use of rootkits like OVERSTEP makes detection especially challenging and underscores the growing sophistication of threat actors targeting aging security infrastructure.

What Undercode Say:

Exploiting the Illusion of Security

This campaign is a textbook case of why relying solely on patching is no longer sufficient. UNC6148 has leveraged a false sense of security among defenders — targeting appliances deemed “safe” post-patch. The key innovation in this attack is not just persistence but invisibility. By using a stealthy rootkit that modifies the boot process and exploits Linux dynamic linker mechanisms like LD_PRELOAD, the attackers operate below the radar of most traditional monitoring tools.

Persistence Is the New Perimeter Breach

The attackers’ use of pre-stolen OTP seeds and credentials means they can walk back into environments long after the initial compromise. This persistence strategy is deeply concerning because it breaks the chain of cause and effect in incident response. Even if forensic teams respond swiftly, they may not find clear signs of how or when the breach occurred due to log wiping and anti-forensic tooling.

Unsupported Hardware Is a Loaded Gun

What makes this campaign even more dangerous is the targeting of end-of-life devices. These appliances no longer receive firmware updates from SonicWall, meaning any newly discovered vulnerabilities — especially zero-days — won’t be patched. Organizations that keep such hardware online are essentially gambling with their security.

Hybrid Threats: A New Era of Cybercrime

Evidence linking UNC6148’s campaign to ransomware operations like Abyss/VSOCIETY shows how financially motivated actors are layering their strategies. The use of “World Leaks” to publish stolen data adds an extortion element, further increasing the pressure on victims to pay or face reputational ruin.

Recommended Defense Measures

The path forward must include drastic measures: replacing all unsupported devices, resetting every form of secret (from OTP seeds to TLS keys), and doing deep offline forensics. Simply patching won’t work. Security teams should implement behavior-based detection to monitor for unusual preload library usage or unauthorized script modifications.

The Underestimated Risk of Linux-Based Appliances

While much focus in cybersecurity is on Windows or cloud-native threats, this incident highlights how Linux-based embedded appliances are vulnerable, particularly when they fall off the vendor’s update cycle. SonicWall’s older hardware has now become a lucrative entry point for elite threat actors.

Strategic Recommendations for Enterprises

Enterprises must consider hardware lifecycle management a critical component of their cybersecurity posture. Running devices past their support horizon must trigger a mandatory security review. Additionally, organizations should conduct tabletop exercises that include legacy hardware compromise scenarios — not just phishing or ransomware outbreaks.

SonicWall’s Responsibility

Vendors like SonicWall must play a role in ensuring customers are aware of lifecycle risks. While end-of-life status is typically announced, organizations often fail to act. Stronger, louder vendor communication and tooling for detection on legacy platforms could help prevent similar breaches in the future.

🔍 Fact Checker Results:

✅ UNC6148 has been officially tracked by GTIG and Mandiant as a threat actor using OVERSTEP
✅ The OVERSTEP malware modifies boot sequences and uses LD_PRELOAD rootkit techniques
✅ At least one victim’s data appeared on the “World Leaks” site, linking it to ransomware

📊 Prediction:

🔮 As more organizations neglect to replace unsupported SonicWall appliances, threat actors will continue exploiting them with highly persistent rootkits.
🔮 The use of anti-forensic techniques will likely increase across campaigns, making detection even more difficult for blue teams.
🔮 Future attacks may expand beyond SonicWall, targeting other legacy appliances like Fortinet or Palo Alto devices nearing end-of-life status.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin