SonicWall SMA devices persistently infected with stealthy OVERSTEP backdoor and rootkit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20035 | Authenticated OS Command Injection in SonicWall SMA100 Appliances CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited. Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks. | 6.5 | 4% | KEV |
| large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k) | |
| CVE-2021-20039 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to in Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. NVD description · AI analysis pending | 8.8 | 79% | PoC |
| — | |
| CVE-2024-38475 | Improper Output Escaping in Apache HTTP Server mod_rewrite Enables File Disclosure/Code Execution CVE-2024-38475 is an improper escaping of output flaw (CWE-116) in the mod_rewrite module of the Apache HTTP Server. It is triggered when mod_rewrite maps a request URL to a filesystem location and mishandles encoded characters, allowing a crafted request to reach files that the server is permitted to serve but that were never intentionally or directly reachable by any URL. An attacker can abuse this to disclose source code (for example, serving raw application files) or, depending on the server's configuration and handlers, achieve code execution. Any Apache HTTP Server deployment that uses mod_rewrite is potentially affected; the source data does not specify the vulnerable version range. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Inventory Apache HTTP Server deployments, prioritize internet-facing ones, and check whether mod_rewrite is in use (RewriteRule directives in server config, virtual hosts, or .htaccess files); upgrade to the vendor's fixed release, 2.4.60 or later. If immediate upgrade is not possible, follow vendor guidance to harden or constrain mod_rewrite rules, and treat the issue as actively exploited per CISA KEV, applying BOD 22-01 mitigations for cloud service usage or discontinuing use if mitigation is unavailable. | 9.1 | 100% | KEV |
| masslikely hundreds of thousands to over a million internet-exposed Apache HTTP Server instances, with only the mod_rewrite-enabled subset vulnerable | |
| CVE-2025-32819 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file po A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. NVD description · AI analysis pending | 8.8 | 6% | PoC |
| — |
Full article1,120 words · extracted from helpnetsecurity.com · click to collapse
Unknown intruders are targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances and deploying a novel, persistent backdoor / rootkit, analysts with Google’s Threat Intelligence Group (GTIG) have warned.
The analysts say UNC6148 – as they dubbed the threat group – is likely financially motivated.

“An organization targeted by UNC6148 in May 2025 was posted to the ‘World Leaks’ data leak site (DLS) in June 2025, and UNC6148 activity overlaps with publicly reported SonicWall exploitation from late 2023 and early 2024 that has been publicly linked to the deployment of Abyss-branded ransomware (tracked by GTIG as VSOCIETY),” they noted.
SonicWall appliances saddled with malware
In this latest campaign, UNC6148 leveraged compromised local administrator credentials and possibly an unknown zero-day remote code execution vulnerability to deploy the OVERSTEP backdoor.
Google’s investigators have been unable to pinpoint how the attackers managed to obtain the admin credentials they used in the attack. It’s possible that they sourced them from infostealer logs or credential marketplaces, the GTIG experts noted, but it’s more likely that they’ve leveraged a known vulnerability prior to the targeted SMA appliance being updated to the latest firmware version.
(Which specific vulnerability was exploited for this part of the attack is currently unknown, though some have been mentioned as possibly used: CVE-2021-20035, CVE-2021-20039, CVE-2024-38475, or CVE-2025-32819.)
The attackers exfiltrated the credentials back in January 2025, and used them in June 2025 to establish an SSL VPN session to the targeted SMA appliance, then spawned a reverse shell – something that was deemed impossible due to how the appliances are designed.
Google’s incident response arm Madiant and the SonicWall Product Security Incident Response Team (PSIRT) still don’t know how the attackers established this reverse shell, and posit that the action was made possible by exploiting an unknown vulnerability.
Through the reverse shell, the threat actors:
- Performed reconnaissance
- Performed file manipulation
- Exported settings from the SMA appliance, (apparently) modified them to include new rules for their infrastructure to ensure uninterrupted operations, and imported them back to the SMA appliance
- Deployed the OVERSTEP backdoor
- Assured the backdoor’s persistence by hiding a file and modifying another legitimate file on the system
“Once the deployment of OVERSTEP was complete, the threat actor cleared the system logs and rebooted the firewall to trigger the execution of OVERSTEP. The changes [made] meant that whenever the appliance was rebooted, the OVERSTEP binary would be loaded into the running filesystem on the appliance,” the analysts explained.
Have your SonicWall devices been compromised?
The OVERSTEP backdoor:
- Hijacks standard API functions
- Establishes a reverse shell
- Exfiltrates passwords from the compromised host
- Implements usermode rootkit capabilities and attempts to delete select entries from log files to hide its presence and its components
- Receives commands embedded within web requests
The malware’s capabilities allowed the attackers to hide what (if anything) they did on the system after they compromised the appliance.
“The primary risk stems from OVERSTEP’s functionality to steal sensitive files. Its ability to exfiltrate the persist.db database and certificate files from the /etc/EasyAccess/var/cert directory gives the attacker credentials, OTP seeds, and certificates. While we did not directly observe the weaponization of this stolen data, it creates a clear path for persistent access,” the analysts said.
They’ve shared host and network-based indicators of compromise (IoCs) related to this campaing and urged defenders to analyze disk images and peripheral log sources for signs of compromise.
“If evidence of compromise is detected, organizations should take immediate steps to contain the threat,” they noted, and advised isolating the appliance(s), preserving disk images and telemetry for a full forensic investigation and, if needed, calling in incident responders to help with the investigation.
Finally, they should consider all user credentials and certificates with private keys stored on the appliance compromised, and should reset / revoke / reissue them.
SonicWall comments
“SonicWall is aware of the recent report by Google Threat Intelligence Group (GTIG) identifying an active campaign targeting SMA 100 series appliances. We’ve been working closely with GTIG throughout this process and appreciate their responsible disclosure and continued partnership in protecting customers and the broader security community,” a SonicWall representative told Help Net Security.
“In response to the evolving threat landscape—and in alignment with our commitment to transparency and customer protection—SonicWall will accelerate the end-of-support date for the SMA 100 series from October 1, 2027, to December 31, 2025. The SMA 100 has already reached end-of-sale status, as reflected in our Product Lifecycle Table, and this update aligns with our long-term strategy and industry direction.”
They also noted that SonicWall has been actively guiding customers toward more modern, secure solutions such (e.g. the Cloud Secure Edge service and the SMA 1000 series), and that detailed migration guidance to SonicWall’s Zero Trust solutions will be shared with customers and partners in the coming weeks.
“We understand that not all customers have transitioned yet, and we remain committed to supporting existing SMA 100 deployments with firmware updates throughout the remaining lifecycle. These updates may become more frequent as we prioritize risk mitigation and the ongoing protection of our user base,” they added.
UPDATE (July 17, 2025, 02:30 a.m. ET):
“[Our report] is based on the culmination of multiple investigations,” Zander Work, Senior Security Engineer, Google Threat Intelligence Group, told Help Net Security.
He also told us that:
- Although they didn’t observe any lateral movement at the time, they suspect the attackers were interested in using the stolen credentials to move laterally within the victim’s network
- Based on the forensic data they recovered, they suspect the 0-day vulnerability used to deploy OVERSTEP may have required administrative credentials to successfully exploit
“If organizations identify any of the signs of compromise discussed [in our report], we recommend capturing available forensic artifacts prior to conducting any remediation activities,” he noted.
“Based on SonicWall’s guidance, we recommend SMA 100 series appliance owners to consider upgrading or replacing their appliances with newer products that aren’t end-of-life.”
UPDATE (August 5, 2025, 11:30 a.m. ET):
Legacy SSL VPNs are difficult to manage, prone to vulnerabilities, and “are constantly in the spotlight with a steady stream of CVEs that demand urgent patching, each one a new risk, a new fire drill, and another stain on your team’s time,” SonicWall acknowledged last Friday.
With the end-of-support date for the SMA100 series being just around the corner – and likely tired of being constantly in the news due to attackers compromising these devices – the company is trying to entice customers who still use those appliances to switch to Cloud Secure Edge, its cloud-delivered remote access solution, by offering a trade up promotion.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/16/sonicwall-sma-devices-persistently-infected-with-stealthy-overstep-backdoor-rootkit/