Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor


Google Threat Intelligence Group (GTIG) has identified an ongoing campaign by a suspected financially-motivated threat actor we track as UNC6148, targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.

GTIG assesses with high confidence that UNC6148 is leveraging credentials and one-time password (OTP) seeds stolen during previous intrusions, allowing them to regain access even after organizations have applied security updates. Evidence for the initial infection vector was limited, as the actor’s malware is designed to selectively remove log entries, hindering forensic investigation; however, it is likely this was through the exploitation of known vulnerabilities.

Read more…
Source: Mandiant/GTG


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Duvel forced to shut breweries after cyber attack

    March 9, 2024

    Belgian brewer Duvel has insisted it will have enough beer to keep supply flowing after it was hit by a cyber attack that brought production to a standstill. The company, one of the best-known Belgian beer brands, was hit by a suspected ransomware attack on Tuesday night that shut down five of its production facilities, four ...

  • FBI Report Reveals Americans Lost Staggering $3.94 Billion to Crypto Investment Scams in 2023

    March 9, 2024

    The surge in cryptocurrency scams in 2023, as reported by the FBI, underscores the growing prevalence of digital currency in online crime. With losses reaching $3.94 billion, a 53% increase from the previous year, these scams represent a significant portion of overall investment frauds, which amounted to $4.57 billion. Cryptocurrency scams encompass a range of deceptive ...

  • Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities

    March 8, 2024

    On January 10, 2024, Ivanti published a security advisory regarding two vulnerabilities in Ivanti Connect Secure VPN. These vulnerabilities, which were exploited in the wild, are identified as CVE-2023-46805 and CVE-2023-21887. The exploitation of these vulnerabilities was quickly adopted by a number of threat actors, resulting in a broad range of malicious activities. Check Point Research ...

  • Patch now! VMWare escape flaws are so serious even end-of-life software gets a fix

    March 8, 2024

    VMWare has issued secuity fixes for its VMware ESXi, Workstation, Fusion, and Cloud Foundation products. It has even taken the unusual step of issuing updates for versions of the affected software that have reached thier end-of-life, meaning they would normally no longer be supported. This flaws affect customers who have deployed VMware Workstation, VMware Fusion, and/or ...

  • Belgium’s largest coffee roaster falls victim to cyber attack

    March 8, 2024

    Coffee Beyers from the Belgian town of Puurs-Sint-Amands has fallen victim to a cyber attack. Hackers managed to break into the company’s computer systems on Thursday. Cybercriminals are clearly targeting Belgian beverage producers this week. During the night from Tuesday to Wednesday, brewery Duvel Moortgat found traces of a break-in on its servers. Read more… Source: Techzine  

  • PetSmart warns customers of credential stuffing attack

    March 7, 2024

    Pet retail company PetSmart has emailed customers to alert them to a recent credential stuffing attack. Credential stuffing relies on the re-use of passwords. Take this example: User of Site A uses the same email and password to login to Site B. Site A gets compromised and those login details are exposed. People with access to ...