Also known as: tracked as, Storm-0978 targeting defense, government entities in Europe, North America
UNC6148 is an emerging threat actor that combines social engineering with advanced exploitation techniques to target high–value sectors such as defense, finance, government, non‑profit and critical infrastructure. The group spearphishes defenders by delivering malicious Microsoft Office documents that trigger the CVE‑2023‑36884 remote code execution vulnerability in SonicWall Secure Mobile Access (SMA) appliances. After compromising a device they install an advanced kernel‑level backdoor known as OVERSTEP, which modifies the boot process, deletes system logs and establishes reverse shells for command and control. OVERSTEP’s persistence mechanisms include credential theft through stolen OTP seeds and valid accounts, allowing the actor to retain access even after patches are applied. In addition to data exfiltration and surveillance, UNC6148 has been linked to ransomware operations comparable to VSOCIETY, indicating a willingness to leverage financial extortion once footholds are established. The adversary’s tactics demonstrate high sophistication: they exploit zero‑day or high‑severity CVEs (e.g., CVE‑2024‑38475), use privilege escalation via process injection and system service installation, and employ obfuscation to evade detection. Their blend of social engineering, device exploitation, and stealth persistence makes them a significant threat to organizations that rely on SonicWall appliances or other similar security products.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6148 (also known as Storm‑0978) is a financially motivated adversary that targets defense and government organizations in Europe, North America and other regions by spearphishing with malicious Office attachments exploiting CVE‑2023‑36884 on SonicWall Secure Mobile Access appliances. The group deploys the persistent OVERSTEP rootkit, reuses stolen OTP seeds for continued access and has evidence of ransomware deployment via a VSOCIETY‐like campaign. Their operations emphasize stealth persistence, credential reuse and exploitation of zero‑day vulnerabilities in critical infrastructure devices.
Goals & Targeting
UNC6148’s strategic objectives revolve around financial gain through direct extortion (ransomware), data theft, and long‑term espionage against defense and government entities. By reusing stolen OTP seeds and valid administrator credentials they secure persistent footholds across multiple devices, enabling continuous data exfiltration or leverage for future attacks. Their targeting profile reflects a preference for critical infrastructure and high‑security organizations where the impact of ransomware or leaked sensitive data can be maximized.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6148 repeatedly combines spearphishing campaigns with exploitation of newly disclosed SonicWall vulnerabilities to gain remote code execution on Secure Mobile Access appliances. Once the device is compromised, they install the OVERSTEP rootkit and leverage stolen OTP credentials to maintain long‑term access, often adding ransomware payloads from a VSOCIETY‑like family. The group shows a moderate operational tempo with repeat patterns of zero‑day exploitation, credential reuse, and stealth persistence targeting defense, government and critical infrastructure customers in Europe, North America, China, Australia, Taiwan, the United States, Japan and other regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available reports, threat intelligence feeds and documented exploitation activity. While the key techniques, tactics, and tool usage are well‑documented, gaps remain regarding precise attribution evidence (e.g., clear linking of all observed behaviors to a single group), operational timelines, and the full scope of ransomware capabilities. Overall confidence is high for identified behaviors but moderate for unproven claims such as repeated reuse of OTP credentials across unrelated attacks.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics