Google finds custom backdoor being installed on SonicWall network devices

Google finds custom backdoor being installed on SonicWall network devices

The Google Threat Intelligence Group has revealed alarming findings regarding SonicWall Secure Mobile Access (SMA) appliances, which are crucial for managing and securing mobile device access at the perimeter of enterprise networks. These devices, now considered end-of-life, are no longer receiving updates aimed at enhancing stability and security, leaving them vulnerable to cyber attacks. Despite this, many organizations still rely on these systems, making them attractive targets for a hacking group identified as UNC6148. In a report released on Wednesday, GTIG explicitly advises organizations using SMA appliances to conduct thorough analyses to assess whether their systems have been compromised. They recommend obtaining disk images for forensic purposes, cautioning that the rootkit anti-forensic capabilities may interfere with the investigation process. To capture these disk images effectively, organizations might need to collaborate directly with SonicWall. Details surrounding the attacks remain sparse. It has been established that the hackers are leveraging leaked local administrator credentials to carry out their operations; however, the source of these credentials is still a mystery. Furthermore, the specific vulnerabilities being exploited by UNC6148 have yet to be identified. The report indicates that attackers install custom backdoor malware called Overstep, which enables them to selectively erase log entries, complicating forensic efforts. Additionally, there is speculation that the group may possess a zero-day exploit, targeting vulnerabilities that are not yet publicly known. The cybersecurity community is on high alert as investigations continue into the methods and impacts of these breaches.

Sources : Ars Technica

Published On : Jul 16, 2025, 20:30

Automotive
Waymo Faces Senate Scrutiny Over Remote Assistance Practices

In a recent Senate Commerce Committee hearing, Waymo's Chief Safety Officer, Mauricio Peña, took the spotlight as he dis...

TechCrunch | Feb 22, 2026, 17:20
Waymo Faces Senate Scrutiny Over Remote Assistance Practices
Cybersecurity
Government Alerts India AI Impact Summit Attendees About Phishing Threats

The government has taken proactive steps to inform participants of the India AI Impact Summit 2026 about a concerning ph...

Business Today | Feb 22, 2026, 17:35
Government Alerts India AI Impact Summit Attendees About Phishing Threats
Startups
Mastercard Unveils AI-Driven Commerce Framework Tailored for India

During the India AI Impact Summit 2026, Mastercard introduced its innovative Agentic Commerce framework, which harnesses...

Business Today | Feb 23, 2026, 05:05
Mastercard Unveils AI-Driven Commerce Framework Tailored for India
AI
How China's AI Landscape is Shaping Innovative Product Development

The AI startup ecosystem in China is experiencing significant growth, showcasing a distinct approach to product developm...

Business Insider | Feb 23, 2026, 24:10
How China's AI Landscape is Shaping Innovative Product Development
Startups
Bill Gurley Encourages Bold Career Moves Amid AI Revolution

For almost 30 years, Bill Gurley has been a key figure in Silicon Valley, recognized for his influential role as a gener...

TechCrunch | Feb 22, 2026, 21:45
Bill Gurley Encourages Bold Career Moves Amid AI Revolution
View All News