Hacker using backdoor to exploit SonicWall Secure Mobile Access to steal credentials




  • A threat actor has used a patched vulnerability in SonicWall software
  • The group is tracked as UNC6148
  • This allowed UNC6148 to potentially steal credentials and deploy ransomware

A financially motivated threat actor, tracked by Google’s Threat Intelligence Group as UNC6148, has been observed targeting patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.

These attacks, Google determines with ‘high confidence’, are using credentials and one-time passwords (OTP) seeds that were obtained through previous instructions, which has allowed them to re-access even after organizations have updated their security.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *