By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
Notification Show More
Latest News
Osimhen scores in first game since Napoli mocking post
Insider
Haiti crisis: Can Kenyan police officers defeat the gangs?
Insider
The untold story of CFB’s ultimate party crasher: Meet the fan who led the Vols onto the field for the 1998 title game
Sports
Investors’ enthusiasm for Japanese stocks has gone overboard
Economy
Lone Star among suitors racing to devour tinned food giant Princes | Business News
Business
Aa
  • Home
  • Politics
  • Business
  • LifeStyle
  • Sports
  • Entertainment
  • Health
  • Tech
Reading: SonicWall is being attacked by some very persistent malware
Share
Aa
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
  • ES Money
  • U.K News
  • Entertainment
  • Science
  • Technology
  • Insider
Search
  • Home
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Life Style
  • Tech
Have an existing account? Sign In
Follow US
Confluence News - Breaking News, Latest News and Videos > Blog > Tech > SonicWall is being attacked by some very persistent malware
Tech

SonicWall is being attacked by some very persistent malware

Last updated: 2023/03/10 at 4:36 PM
Tech Radar Pro
Share
SHARE

SonicWall devices are being attacked by some very persistent malware (opens in new tab) that is capable of surviving through multiple firmware updates, experts have claimed.

Cybersecurity researchers from Mandiant and SonicWall recently discovered a custom-built malware, designed specifically for SonicWall Secure Mobile Access (SMA) appliances, most likely designed by a Chinese threat actor dubbed UNC4540. 

Its features show a “deep understanding” of the devices it was built for, and the malware is designed for espionage, the researchers claim, as it’s capable of stealing user passwords, as well as providing shell access. 

Establishing remote access

“The overall behavior of the suite of malicious bash scripts shows a detailed understanding of the appliance and is well tailored to the system to provide stability and persistence,” Mandiant said.

The main module can steal hashed credentials of all users that are logged into the compromised endpoints, copy them into a text file and ship them out to be decrypted elsewhere. Another module establish a reverse shell for easy remote access. Also, the researchers found a module that adds a small patch to a legitimate SonicWall binary whose purpose they still weren’t able to determine.

The researchers also couldn’t determine which vulnerability the attackers used to compromise these devices with malware, but they’re suspecting the malware was deployed years ago and successfully lived through multiple firmware updates. They believe the initial compromise could have been done back in 2021. 

To protect your devices against unknown threats such as this one, the best course of action is to apply the latest security updates. SonicWall’s latest version for targeted appliances is 10.2.1.7, the publication says, adding that the patch includes File Integrity Monitoring (FIM) and anomalous process identification, two features “which should detect and stop this threat.”

“In recent years Chinese attackers have deployed multiple zero-day exploits and malware for a variety of internet facing network appliances as a route to full enterprise intrusion, and the instance reported here is part of a recent pattern that Mandiant expects to continue in the near term,” Mandiant concluded.

Via: BleepingComputer (opens in new tab)



Source link

You Might Also Like

Billions of passwords and email addresses have been leaked online – so change your logins now

9 things announced at the Meta Connect 2023 event

Scientists transformed a cockroach into a remote-controlled zombie cyborg using an electrical backpack — and no, there’s absolutely nothing to be afraid of

PlayStation boss Jim Ryan is leaving Sony

Tech Radar Pro March 10, 2023
Share this Article
Facebook Twitter Email Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News

Turkey summons Norwegian ambassador over Quran protest permission

February 2, 2023
‘Harry Potter’ star Tom Felton details past struggle with alcoholism in new memoir
One of the best RPGs of all time is coming to Game Pass
Greece Train Crash Kills at Least 36
Quordle today – hints and answers for Saturday, September 16 (game #600)
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

Categories

  • ES Money
  • Insider
  • Science
  • Technology
  • LifeStyle

About US

We influence 20 million users and is the number one business and technology news network on the planet.
Quick Link
  • Economy
  • Politics
  • Life Style
  • Contact Us
Top Categories
  • Business
  • Tech
  • Top
  • Health
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© confluencenews. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?