A persistent threat actor has been actively exploiting vulnerabilities in SonicWall SMA appliances by deploying the Oversteer backdoor, leading to ongoing cyberattacks. These attacks target SonicWall's Secure Mobile Access (SMA) devices, which are widely used for secure remote access. The attackers leverage known vulnerabilities to gain unauthorized access and implant the Oversteer backdoor, enabling persistent control over compromised systems. This campaign highlights the critical need for organizations to promptly apply security patches and enhance monitoring of their SonicWall SMA environments. The Oversteer backdoor facilitates stealthy operations, data exfiltration, and potential lateral movement within networks, posing significant risks to affected enterprises. Security researchers emphasize the importance of comprehensive incident response and threat hunting to detect and mitigate these intrusions effectively. Organizations are urged to review their SonicWall SMA configurations, update firmware, and implement robust security controls to defend against this evolving threat. This ongoing attack campaign underscores the sophisticated tactics employed by threat actors targeting VPN and remote access infrastructure, necessitating heightened vigilance and proactive cybersecurity measures.
This Cyber News was published on www.darkreading.com. Publication date: Wed, 24 Sep 2025 13:00:11 +0000