Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6148

Also known as: tracked as, Storm-0978 targeting defense, government entities in Europe, North America

Description

UNC6148 is an emerging threat actor that combines social engineering with advanced exploitation techniques to target high–value sectors such as defense, finance, government, non‑profit and critical infrastructure. The group spearphishes defenders by delivering malicious Microsoft Office documents that trigger the CVE‑2023‑36884 remote code execution vulnerability in SonicWall Secure Mobile Access (SMA) appliances. After compromising a device they install an advanced kernel‑level backdoor known as OVERSTEP, which modifies the boot process, deletes system logs and establishes reverse shells for command and control. OVERSTEP’s persistence mechanisms include credential theft through stolen OTP seeds and valid accounts, allowing the actor to retain access even after patches are applied. In addition to data exfiltration and surveillance, UNC6148 has been linked to ransomware operations comparable to VSOCIETY, indicating a willingness to leverage financial extortion once footholds are established. The adversary’s tactics demonstrate high sophistication: they exploit zero‑day or high‑severity CVEs (e.g., CVE‑2024‑38475), use privilege escalation via process injection and system service installation, and employ obfuscation to evade detection. Their blend of social engineering, device exploitation, and stealth persistence makes them a significant threat to organizations that rely on SonicWall appliances or other similar security products.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Government
Non profit
Manufacturing
Telecommunications
Aerospace
Critical infrastructure
Education
Information technology
Media

Targeted Countries / Regions

CN
AU
TW
US
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 6 hours ago

Executive Summary

UNC6148 (also known as Storm‑0978) is a financially motivated adversary that targets defense and government organizations in Europe, North America and other regions by spearphishing with malicious Office attachments exploiting CVE‑2023‑36884 on SonicWall Secure Mobile Access appliances. The group deploys the persistent OVERSTEP rootkit, reuses stolen OTP seeds for continued access and has evidence of ransomware deployment via a VSOCIETY‐like campaign. Their operations emphasize stealth persistence, credential reuse and exploitation of zero‑day vulnerabilities in critical infrastructure devices.

Goals & Targeting

UNC6148’s strategic objectives revolve around financial gain through direct extortion (ransomware), data theft, and long‑term espionage against defense and government entities. By reusing stolen OTP seeds and valid administrator credentials they secure persistent footholds across multiple devices, enabling continuous data exfiltration or leverage for future attacks. Their targeting profile reflects a preference for critical infrastructure and high‑security organizations where the impact of ransomware or leaked sensitive data can be maximized.

Enhanced Description

Key Capabilities

  • Spearfishing with malicious Office attachments delivering CVE‑2023‑36884 exploit
  • Exploitation of zero‑day or known vulnerabilities in SonicWall SMA appliances (e.g., CVE‑2024‑38475) for remote code execution
  • Deployment of the persistent OVERSTEP rootkit that modifies boot process and removes logs
  • Credential theft via stolen OTP seeds and compromised valid accounts
  • Establishment of reverse shells for command and control
  • Ransomware deployment linked to VSOCIETY family
  • Data exfiltration and manipulation of system files

MITRE ATT&CK Tactics

Command and Control
Credential Access
Defense Evasion
Discovery
Exfiltration
Execution
Initial Access
Persistence
Privilege Escalation

ATT&CK Techniques

T1003
T1021
T1055
T1068
T1070.004
T1071
T1078
T1082
T1105
T1133
T1205
T1505
T1554
T1560
T1566.001
T1572
T1584
T1588
T1594
T1595

Software / Tooling

OVERSTEP
VSOCIETY

Campaigns & Victims

UNC6148 repeatedly combines spearphishing campaigns with exploitation of newly disclosed SonicWall vulnerabilities to gain remote code execution on Secure Mobile Access appliances. Once the device is compromised, they install the OVERSTEP rootkit and leverage stolen OTP credentials to maintain long‑term access, often adding ransomware payloads from a VSOCIETY‑like family. The group shows a moderate operational tempo with repeat patterns of zero‑day exploitation, credential reuse, and stealth persistence targeting defense, government and critical infrastructure customers in Europe, North America, China, Australia, Taiwan, the United States, Japan and other regions.

IOC Patterns

  • Domain

Recommended Actions

  • Patch all SonicWall SMA devices promptly to remediate CVE‑2023‑36884 and CVE‑2024‑38475; keep firmware up to date
  • Rotate or revoke OTP seeds on SMA appliances and enforce MFA for privileged accounts
  • Deploy endpoint detection and response (EDR) solutions capable of detecting kernel‑level rootkits such as OVERSTEP
  • Monitor for anomalous log deletion, boot configuration changes, and reverse shell patterns
  • Implement network segmentation and perimeter defenses around critical security appliances
  • Set up intrusion detection systems tuned to identify exploitation attempts targeting SonicWall firmware

Suggested Tags

UNC6148
Storm-0978
Spearphishing Attachment
Credential Theft
Backdoor
Rootkit
Zero-Day RCE
Microsoft Office CVE
Phishing Campaign
Ransomware Extortion
CVE-2023-36884
OVERSTEP
Defense Entities
Government Entities

Confidence Assessment

The analysis is based on publicly available reports, threat intelligence feeds and documented exploitation activity. While the key techniques, tactics, and tool usage are well‑documented, gaps remain regarding precise attribution evidence (e.g., clear linking of all observed behaviors to a single group), operational timelines, and the full scope of ransomware capabilities. Overall confidence is high for identified behaviors but moderate for unproven claims such as repeated reuse of OTP credentials across unrelated attacks.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 IPv4 Address 1 Filename 1

References

  1. www.fortinet.com — Cited by web research for: Storm-0978 targeting defense
  2. attack.mitre.org — Cited by web research for: T1595
  3. www.show.it — Cited by web research for: GitHub
  4. cloud.google.com — Cited by web research for: Cursor
  5. cloud.google.com — Cited by web research for: CVE-2024-38475
  6. https://cyberpress.org/sonicwall-sma-devices-targeted-by-0-day-rce/ — Cited by AI analysis.

Intel Summary

29

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Zero-Day Exploitation
Backdoor / C2
Data Exfiltration
Financial Motivation
Network Appliances
Rootkit Activity
UNC6148
Storm-0978
Spearphishing Attachment
Credential Theft
Backdoor
Rootkit
Zero-Day RCE
Microsoft Office CVE
Phishing Campaign
Ransomware Extortion
CVE-2023-36884
OVERSTEP
Defense Entities
Government Entities

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.