Listen to this Post

Stealth Malware Targets Legacy Systems With Shocking Precision
A sophisticated new cyberattack campaign is raising red flags in the cybersecurity world, targeting aging SonicWall Secure Mobile Access (SMA) 100 Series devices with a never-before-seen malware dubbed OVERSTEP. Deployed by an advanced persistent threat group tracked as UNC6148, this user-mode rootkit is far from ordinary. It modifies the boot process of SonicWall devices that, while fully patched, are no longer officially supported. The malware is designed to maintain stealthy persistence, steal administrator credentials, and enable ongoing access for further attacks. Researchers from Google’s Threat Intelligence Group (GTIG) have traced the attacks back to late 2023, with the most recent compromise occurring in May 2025.
Adding to the severity, the stolen data from victims was published on World Leaks, the rebranded platform of the infamous Hunters International, suggesting not just data theft but a ransomware-extortion element. The attack also appears to be connected to the Abyss ransomware, hinting at a broader, more dangerous infrastructure behind the scenes. Though the entry point remains unclear, experts believe UNC6148 may have leveraged known vulnerabilities to steal admin credentials before firmware updates could close the gaps. What’s more concerning is the use of reverse shells and stealth techniques that evade even the most prepared incident response teams.
A Complex Web of Exploits and Evasion Techniques
UNC6148 has shown alarming expertise in compromising end-of-life (EoL) SonicWall SMA appliances, which are still in use in many enterprises for secure remote access to internal resources. GTIG suspects that initial access may have involved known n-day vulnerabilities, such as CVE-2024-38475, which allows attackers to obtain local admin credentials and session tokens. While unconfirmed, this flaw could be the critical key used to infiltrate systems and deploy the OVERSTEP backdoor.
Once access was achieved, attackers initiated a reverse shell connection—something not normally possible with these devices—raising suspicion of an unknown zero-day exploit. From there, they modified policies to whitelist their own IPs and implanted the OVERSTEP malware via base64 decoding and .ELF binary deployment. The malware was further embedded into the system using log-clearing techniques to remove traces of activity. With OVERSTEP in place, UNC6148 achieved full system persistence, credential theft (including OTP seeds and certs), and long-term infiltration capability.
The rootkit operates by injecting itself every time an executable is launched, making it almost impossible to detect through traditional monitoring. GTIG researchers also noted its anti-forensic features, which help the attackers cover their tracks by deleting logs and avoiding any command history.
What Undercode Say:
Persistent Threats Are Moving Into Forgotten Corners of Infrastructure
The OVERSTEP case is a chilling reminder of how neglected or unsupported hardware can become a goldmine for attackers. SonicWall’s SMA 100 Series, widely deployed across enterprises, is a prime example of technology that continues to serve critical functions without receiving full security support. The danger lies in this blind spot. Organizations often assume that patching is sufficient, but legacy status introduces unique vulnerabilities, especially when firmware updates stop and hardware falls out of lifecycle protection.
UNC6148 has demonstrated high technical acumen by not only discovering an apparent zero-day exploit but also orchestrating a multi-stage attack involving credential theft, policy manipulation, stealth rootkit deployment, and data exfiltration. Their use of reverse shells on a system designed to reject such operations indicates either a deep familiarity with SonicWall’s architecture or the discovery of undocumented system behavior. This elevates UNC6148 from a mere hacker collective to a state-level or highly funded cybercriminal group.
Furthermore, the ability of OVERSTEP to persist through reboots, delete logs, and maintain invisibility transforms this from a simple malware case into a serious nation-grade espionage tool. Its dual capacity for both ransomware deployment (through ties with Abyss/VSOCIETY) and credential harvesting shows that UNC6148 is interested not just in money, but in control, surveillance, and prolonged access.
The wider implication is stark: even fully patched systems are vulnerable if they’re no longer supported. End-of-life hardware creates a security void. If these devices aren’t replaced or segregated from sensitive networks, they act like open windows in a sealed house.
This case also shows that attackers are blending old techniques with new tools. Stealing credentials using known flaws, masking operations with anti-forensics, and dropping rootkits through encoded scripts hark back to early 2010s APT playbooks—yet modernized for today’s hybrid cloud enterprise environments.
The publication of stolen data on World Leaks signals a shift toward ransomware-as-public-shaming, similar to what we’ve seen from other ransomware gangs like Clop or LockBit. That adds a reputational risk to the already considerable operational danger.
Organizations using SonicWall must not only check for indicators of compromise but treat these events as signs of larger systemic risk. This isn’t just about one attack—it’s about a broken model of support, responsibility, and lifecycle security in network infrastructure.
Response Time is Everything
Rapid identification, disk imaging, and isolation are now the minimum standard for dealing with threats like OVERSTEP. Traditional logs are useless when attackers can delete them. Analysts must turn to volatile memory analysis, firmware integrity checks, and behavioral analytics that detect abnormalities at the kernel level. Without this shift in approach, such malware will remain invisible.
Vendors, too, need to evolve. If devices are marked EoL, then security tooling must be integrated to provide real-time alerts—or vendors must clearly guide clients to migrate. Too many businesses unknowingly operate vulnerable hardware that attackers like UNC6148 are waiting to exploit.
OVERSTEP could easily become a template for future malware that thrives on forgotten systems. Its modular design, stealth persistence, and ability to survive reboots will likely inspire copycat operations. And unless action is taken now, we’ll see many more legacy-driven breaches throughout 2025 and beyond.
🔍 Fact Checker Results:
✅ OVERSTEP malware has been verified by Google’s Threat Intelligence Group
✅ Attackers targeted EoL SonicWall SMA 100 Series appliances
✅ Reverse shell and rootkit features were confirmed in post-incident analysis
📊 Prediction:
🔮 Expect OVERSTEP to evolve into a malware family, reused in future APT campaigns
🔐 More legacy appliance-focused threats will surface in the coming year
⚠️ Organizations still relying on unsupported SonicWall systems may face mass exploitation events in late 2025
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




