Here’s the latest:
SonicWall announced a new firmware update to some of their devices that will remove
rootkit malware from devices.
Rootkits are particularly pernicious in that they install deep within a system and allow hackers to do things without being detected. Yikes!
Reading this update, I thought to myself, "Finally a real fix!” For those of you using
SonicWall's SMA100 devices, this is important news for you.
What is happening?
At-risk devices
The update is not for all
SMA devices; it is for
SMA 100 series appliances including
SMA 210,
SMA 410, and
SMA 500v.
The new SonicWall version number of
10.2.2.2-92sv accomplishes two things: it blocks new attacks and will clean out rootkits that are on the device.
The malware
Cyber criminals from a group identified as
UNC6148 have developed a rootkit dubbed OVERSTEP.
Here’s what it does:
- It hides files so you can’t see them
- It provides hackers access where hackers can access
- It retrieves things like certificates, passwords and security codes
Some of these attacks are actually linked to ransomware. This could mean that the damage may grow quickly.
Why this update matters
This is not just any update, it is special because:
- It removes existing malware — instead of simply blocking new malware.
- It extends the lifespan of your old devices.
- It mitigates the risk of a larger attack.
If I had one of these devices, I would update it immediately without a second thought.
What should you do
Here’s the easy checklist:
1. Backup your settings prior to the update.
2. Upgrade to version
10.2.2.2-92sv now.
3. After the update, check your logs for anything unusual.
4. Change your passwords just to be safe.
5. Plan to replace these devices as vendor support is ending.
Conclusion
Bottom Line: The new firmware from
SonicWall is a game changer for anyone that uses
SMA100 series devices. It will not only protect you from future hacks, but it will also clean up the rootkit if you are already infected.