SonicWall has issued an immediate security update for its Secure Mobile Access (SMA) 100 Series appliances to eradicate a persistent rootkit malware dubbed ‘OVERSTEP’.
The update, version 10.2.2.2-92sv, introduces enhanced file‐integrity checks designed to detect and remove malicious components implanted by the OVERSTEP backdoor.
All organizations leveraging the SMA 100 Series (models 210, 410, and 500v) are strongly advised to apply this patch without delay to mitigate ongoing exploitation risks.
Background and Threat Context
SonicWall published Advisory SNWLID-2025-0015, confirming that certain firmware versions of the SMA 100 Series had been targeted by a sophisticated rootkit malware campaign.
Google’s Threat Intelligence Group (GTIG) identified the backdoor’s capability to establish persistent, covert access to enterprise networks, enabling threat actors to move laterally, exfiltrate data, and deploy additional payloads.
Organizations running firmware versions 10.2.1.15-81sv and earlier may be vulnerable to compromise due to insufficient file verification routines in the affected builds.
GTIG’s analysis highlights that OVERSTEP implants a hidden kernel module that intercepts system calls and conceals malicious processes and files from standard operating system utilities.
Although no public exploits have been observed in the wild to date, the potential for undetected persistence and stealthy data exfiltration underscores the criticality of immediate remediation.
Update Details and Deployment Guidance
The fixed firmware, 10.2.2.2-92sv, incorporates additional file checking logic to validate the integrity and authenticity of kernel modules and critical binaries on SMA devices.
Upon installation, the system automatically scans for known indicators of compromise (IOCs) associated with OVERSTEP and removes any detected rootkit components.
SonicWall confirms that no workaround is feasible; only upgrading to the patched version fully eliminates the threat.
To apply the update:
- Log in to the SMA management interface and navigate to System → Firmware & Backups.
- Download the 10.2.2.2-92sv package from SonicWall’s official support portal.
- Upload and install the firmware, then reboot the appliance to complete the process.
- Verify successful removal by reviewing the System → Diagnostics → Firmware Integrity report.
Failure to upgrade promptly may expose networks to unauthorized backdoor access and persistent surveillance.
SonicWall emphasizes that SSL VPN SMA1000 series appliances and SSL-VPN features on firewall products are not affected by this issue.
| CVE | Advisory ID | Affected Product(s) | Fixed Version | CVSS v3 Score |
|---|---|---|---|---|
| N/A | SNWLID-2025-0015 | SMA 100 Series (210, 410, 500v) | 10.2.2.2-92sv and higher | 0.0 |
All SMA 100 Series users should upgrade immediately to protect against the OVERSTEP rootkit and maintain the integrity of remote access infrastructure.
Continuous monitoring for anomalous behaviors and regular firmware audits are recommended to guard against emerging threats.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates