Suspected Chinese UTA0533 linked to exploitation of SonicWall SMA zero-days

 

Suspected Chinese UTA0533 linked to exploitation of SonicWall SMA zero-days

A previously unknown threat actor has been linked to attacks targeting SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, using two zero-day vulnerabilities before they were publicly disclosed.

Cybersecurity firm Volexity, which tracks the group as UTA0533, found that the attacks began as early as June 22, 2026. The attackers exploited two flaws (CVE-2026-15409 and CVE-2026-15410) to gain remote command execution and take over vulnerable devices. SonicWall released security patches for both vulnerabilities earlier this month.

Volexity found that the attackers installed custom malware, including KNUCKLEBALL, which loaded two Java-based tools into a legitimate SonicWall process. The tools (the open-source proxy tool Suo5 and a Behinder-like webshell called ORANGETAIL) allowed the attackers to maintain remote access. The malware also modified system startup files to survive reboots and changed appliance configurations to hide its activity.

Researchers found additional files on the compromised device used for privilege escalation, including a local exploit later assigned CVE-2026-15410. A second appliance showed fewer signs of compromise, likely because it had been rebooted, which removed memory-based malware. However, Volexity found evidence of configuration changes and scripts used to capture unencrypted LDAP traffic.

During the investigation, researchers also discovered a separate issue that could allow attackers to bypass authentication to the SMA control service, a local component responsible for performing system-level operations on the appliance.

“UTA0533 combined multiple zero-day vulnerabilities to compromise SonicWall SMA VPN appliances and obtain root-level access,” the report notes. “With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances. Although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.”

Back to the list