Security News > 2023 > March > Another Malware with Persistence
Here's a piece of Chinese malware that infects SonicWall security appliances and survives firmware updates.
On Thursday, security firm Mandiant published a report that said threat actors with a suspected nexus to China were engaged in a campaign to maintain long-term persistence by running malware on unpatched SonicWall SMA appliances.
The campaign was notable for the ability of the malware to remain on the devices even after its firmware received new firmware.
When an update becomes available, the malware copies the archived file for backup, unzips it, mounts it, and then copies the entire package of malicious files to it.
The malware also adds a backdoor root user to the mounted file.
The malware rezips the file so it's ready for installation.
News URL
https://www.schneier.com/blog/archives/2023/03/another-malware-with-persistence.html