Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor


Google Threat Intelligence Group (GTIG) has identified an ongoing campaign by a suspected financially-motivated threat actor we track as UNC6148, targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.

GTIG assesses with high confidence that UNC6148 is leveraging credentials and one-time password (OTP) seeds stolen during previous intrusions, allowing them to regain access even after organizations have applied security updates. Evidence for the initial infection vector was limited, as the actor’s malware is designed to selectively remove log entries, hindering forensic investigation; however, it is likely this was through the exploitation of known vulnerabilities.

Read more…
Source: Mandiant/GTG


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • FBI investigating attempts to hack Biden-Harris and Trump campaigns

    August 12, 2024

    Federal investigators are looking into whether Iranian hackers targeted individuals associated with the Trump and Biden-Harris campaigns, three people familiar with the investigation confirmed to CBS News. The FBI launched the probes in the early summer, after both presidential campaigns experienced attempted phishing schemes targeting people on the campaign, the sources said. Iran-backed cybercriminals are the ...

  • EU’s Breton says Musk must comply with EU law ahead of Trump interview

    August 12, 2024

    EU industry chief Thierry Breton told billionaire Elon Musk in a letter on Monday he must comply with EU law ahead of Musk’s interview with U.S. presidential candidate Donald Trump on social media platform X. The interview, scheduled for 8PM Eastern Time (0000 Tuesday GMT), will also be accessible to users in the EU, Breton wrote, ...

  • Ongoing Social Engineering Campaign Refreshes Payloads

    August 12, 2024

    On June 20, 2024, Rapid7 identified multiple intrusion attempts by threat actors utilizing techniques, tactics, and procedures (TTPs) that are consistent with an ongoing social engineering campaign being tracked by Rapid7. The initial lure being utilized by the threat actors remains the same: an email bomb followed by an attempt to call impacted users and offer ...

  • 5G network flaws could be abused to let hackers spy on your phone

    August 12, 2024

    5G basebands could be exploited by attackers to allow them to send fake messages to your contacts, or even hand over your credentials using a very real-looking website, experts have warned. Unveiled at the Black Hat cybersecurity conference, a research group from Pennsylvania State University presented their vulnerability sniffing tool 5GBaseChecker. Read more… Source: MSN News Sign up for ...

  • Indirect prompt injection in the real world: how people manipulate neural networks

    August 12, 2024

    Large language models (LLMs) – the neural network algorithms that underpin ChatGPT and other popular chatbots – are becoming ever more powerful and inexpensive. Systems built on instruction-executing LLMs may be vulnerable to prompt injection attacks. A prompt is a text description of a task that the system is to perform, for example: “You are a ...

  • Swiss-based Schlatter says IT network affected by cyberattack

    August 12, 2024

    Engineering company Schlatter Industries’ IT network was attacked with malware on Friday and it can be assumed this was a professional attack, the Switzerland-based company said on Monday. The group was hit on Friday by a cyberattack using malware, and the unknown perpetrators were attempting to “blackmail Schlatter”, it said, disclosing no further details. The group ...