Hacker using backdoor to exploit SonicWall Secure Mobile Access to steal credentials

Hacker using backdoor to exploit SonicWall Secure Mobile Access to steal credentials

Hacker using backdoor to exploit SonicWall Secure Mobile Access to steal credentials


  • A threat actor has used a patched vulnerability in SonicWall software
  • The group is tracked as UNC6148
  • This allowed UNC6148 to potentially steal credentials and deploy ransomware

A financially motivated threat actor, tracked by Google’s Threat Intelligence Group as UNC6148, has been observed targeting patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.

These attacks, Google determines with ‘high confidence’, are using credentials and one-time passwords (OTP) seeds that were obtained through previous instructions, which has allowed them to re-access even after organizations have updated their security.



Source link

Back To Top