SonicWall Disaster: Hackers Exploit Fully Patched Devices in New Global Cyber Assault

Listen to this Post

Featured Image

Cybersecurity’s Latest Nightmare: A Crisis Hidden in Plain Sight

A fresh wave of sophisticated cyberattacks is rattling the cybersecurity community, as threat actors successfully breach fully patched SonicWall SMA 100 appliances—devices that are technically no longer supported by the vendor. Despite organizations believing they were secure, these attacks prove that even updated systems aren’t immune when exploited through old credentials, overlooked backdoors, or stealthy malware tactics. Google’s Threat Intelligence Group has flagged a financially motivated hacking group, UNC6148, as the perpetrator, spotlighting an alarming trend: attackers using advanced persistence techniques to infiltrate networks, bypass detection, and potentially launch ransomware. These incidents underscore a growing crisis in security patching, legacy tech usage, and the cybercrime economy’s shift toward extortion-based models. This revelation couldn’t come at a worse time for enterprises relying on outdated infrastructure to maintain secure remote access.

Persistent Exploits: The Summary of the Latest SonicWall Crisis

A new cyber offensive is targeting companies that continue to use fully updated but end-of-life SonicWall SMA 100 series devices. The Google Threat Intelligence Group has uncovered a campaign spearheaded by UNC6148, a financially motivated threat group. These attackers are leveraging previously stolen administrative credentials to access the now-retired SonicWall remote access VPN devices. Once inside, they perform sophisticated operations like deploying backdoors, conducting surveillance, and preparing systems for possible ransomware attacks. UNC6148’s activities have been ongoing for months and show overlap with previous SonicWall exploitations dating back to late 2023 and early 2024.

What makes these attacks particularly concerning is that SonicWall SMA 100 appliances remain a favorite among cybercriminals. Of the 14 known SonicWall vulnerabilities listed in CISA’s exploited vulnerabilities catalog, nine have been linked to ransomware activity, and seven directly affect the SMA 100 series. Despite issuing firmware updates, SonicWall has acknowledged the critical security landscape and has accelerated the end-of-support timeline for the SMA 100.

In several breaches analyzed by Google and Mandiant, UNC6148 bypassed typical detection methods by erasing log entries, using SSL VPN sessions, and deploying a malware tool known as OVERSTEP. Although it remains unclear how the group initially compromised the systems, possible exploitation of CVEs like CVE-2021-20038, CVE-2024-38475, and others is suspected. Notably, even after organizations updated their firmware, the compromised credentials allowed the attackers to regain access and maintain persistence, which is particularly alarming.

One known victim was listed on the World Leaks data leak site in June, further hinting at UNC6148’s dual strategy of data exfiltration and extortion. Google has yet to confirm how widespread this attack is, but SonicWall admits that many customers have yet to transition to more secure solutions like Cloud Secure Edge or the SMA 1000 series. The advisory suggests that future firmware updates for the SMA 100 series will be released more frequently until support ends. This ongoing threat reinforces the urgency for companies to migrate from legacy infrastructure, enhance identity management practices, and improve incident response capabilities.

What Undercode Say:

Legacy Infrastructure: The Silent Killer

This attack wave throws a harsh spotlight on one of the cybersecurity industry’s long-standing weaknesses—reliance on outdated hardware. Although patched, the SMA 100 series devices are no longer supported, which means they’re operating without the full weight of vendor-backed protection. The fact that hackers are exploiting fully updated yet deprecated systems illustrates a dangerous misconception: patching alone is no longer enough.

Credential Theft: The New Frontline

UNC6148’s exploitation strategy hinges on one crucial element: stolen administrator credentials. It’s a chilling reminder that even airtight software patches can’t compensate for compromised identity systems. Attackers are weaponizing valid credentials to log into devices undetected, establish remote sessions, and quietly manipulate systems at a level normally reserved for IT admins.

Attackers Stay One Step Ahead

UNC6148’s technical sophistication is alarming. The malware not only breaches the system but also erases its own tracks by wiping logs—a tactic typically seen in nation-state operations. Deploying backdoors like OVERSTEP allows the attackers to maintain persistence, even after organizations attempt remediation. These aren’t smash-and-grab ransomware operators; they are calculated, stealthy, and dangerously patient.

Misplaced Trust in Fully Patched Devices

The attack on patched SMA 100 units reveals a systemic flaw in how organizations measure cybersecurity readiness. Many equate “patched” with “protected”, ignoring the broader landscape of attack vectors, especially when credentials are already compromised. UNC6148 exploited the gray area between software updates and credential hygiene.

The Problem with EOL (End-of-Life) Products

SonicWall’s SMA 100 series being out-of-support plays directly into the hands of cybercriminals. Vendors tend to issue fewer urgent alerts and less aggressive patching schedules for legacy products. In this scenario, the vendor has taken the responsible step of urging customers to migrate—but clearly, many haven’t acted in time, which opened the door to these latest attacks.

VPNs: Still a Prime Target

Remote access solutions remain one of the most targeted sectors in cybercrime. VPN appliances, especially those used in hybrid or remote environments, serve as critical chokepoints. Once breached, they can expose entire enterprise networks. This incident should serve as a red flag for companies relying heavily on VPN infrastructure without implementing Zero Trust Network Access (ZTNA).

Limited Visibility, Maximum Risk

Both Google and Mandiant admitted that forensic data is limited, meaning much of what’s known is incomplete or speculative. That raises a red flag about visibility. Organizations must invest in better telemetry, threat hunting, and logging mechanisms to track persistent attackers.

The Economics Behind It

This is not just about data theft. UNC6148’s motivations are clearly financial—targeted data exfiltration, potential ransomware, and public leaks for extortion. With leak sites like World Leaks being used as a weapon, the ransomware-as-a-service model continues to evolve, emphasizing extortion over encryption.

The Urgency of Migration

SonicWall has already recommended transitioning to its Cloud Secure Edge and SMA 1000 alternatives. The problem? Many organizations haven’t yet acted. Migration delays are often due to budget constraints, integration challenges, or simple inertia, but they are proving to be a costly gamble.

Final Takeaway

These attacks are a masterclass in modern intrusion techniques: credential-based access, stealthy persistence, and selective malware deployment. As cybersecurity becomes more complex, relying on legacy systems—even if they are patched—is a ticking time bomb. The SonicWall incident is a wake-up call for every IT and security leader.

🔍 Fact Checker Results:

✅ UNC6148 is actively exploiting fully patched, end-of-life SonicWall SMA 100 devices.
✅ The group uses stolen credentials and deploys the OVERSTEP backdoor for persistence.
❌ No confirmed infection vector or initial access method has been fully verified by researchers.

📊 Prediction:

Expect an increase in targeted attacks on end-of-life network appliances, especially those used for remote access. As more legacy systems remain in place beyond vendor support timelines, financially motivated groups like UNC6148 will continue exploiting these gaps. Enterprises that delay migration or overlook credential hygiene will be prime targets in 2025’s next major ransomware surge. 🔥💻💰

References:

Reported By: cyberscoop.com
Extra Source Hub:
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin