Skip to content
feed: live
>_ 0dayNews
sonicwall
● Breaking

Volexity ties SonicWall SMA1000 zero-days to UTA0533

Volexity attributes the SonicWall SMA1000 zero-day chain to UTA0533, first observed exploitation on June 22, four custom implants staged after.

Volexity ties SonicWall SMA1000 zero-days to UTA0533
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 3 min read

Update to the July 14 KEV brief. Two facts moved from “SonicWall PSIRT says exploited” to sourced attribution and dated timeline.

Attribution. Volexity tracks the actor as UTA0533. Confidence: single named vendor, primary IR firm on the case, no public second-source corroboration yet. No country or crew nexus asserted by Volexity in what has been reported. Treat “UTA0533” as an actor cluster, not an attribution to a known group.

Earliest observed exploitation. June 22, 2026. Per Volexity via BleepingComputer. Confidence: as-observed by Volexity’s IR telemetry — earliest-seen, not earliest-possible. SonicWall’s original SNWLID-2026-0008 advisory landed July 14. That is roughly a three-week zero-day window in which the CVE-2026-15409 unauthenticated SSRF (CVSS 10.0) and CVE-2026-15410 post-auth OS command injection (CVSS 7.2) were live against unpatched SMA1000 6210, 7210, and 8200v appliances.

The implants

Four artifacts named in the Volexity writeup, per BleepingComputer. Descriptions here are role-level; refer to Volexity for the technical detail.

  • KNUCKLEBALL — dropper. Filename observed: deploy_new.py.
  • Sou5 — reverse proxy. Filename observed: agent_wp8.jar. Function: covert access channel back to the appliance.
  • ORANGETAIL — Java webshell. Filename observed: agent_wp9.jar. Function: encrypted payload execution.
  • ROOTRUN — privilege-escalation tool.

Confidence on the four names and roles: as-reported by Volexity via BleepingComputer. IoC file paths in the SonicWall advisory (extraweb_access.log, ctrl-service.log, /var/lib/unit/conf.json) remain the load-bearing artifacts for defenders — check those first.

Timeline

  • June 22, 2026 — earliest observed UTA0533 exploitation, per Volexity IR telemetry.
  • June 22 – July 14 — zero-day window. No public advisory, no patch, active exploitation.
  • July 14 — SonicWall publishes SNWLID-2026-0008 with fixed builds 12.4.3-03453 and 12.5.0-02835. CISA adds both CVEs to KEV the same day. Federal patch deadline: July 17.
  • July 20 — Volexity/BleepingComputer publish the UTA0533 attribution, June 22 first-observed date, and the four implant names.

What this changes for defenders

Nothing about the July 14 patch call has softened. What it adds:

  • Dwell math is no longer a question mark. Any SMA1000 that ran a vulnerable build between June 22 and its patch date is inside the observed exploitation window. That is the population that gets a compromise-scale review, not a patch-and-move-on.
  • IoCs to hunt on now, not later. Volexity’s writeup names KNUCKLEBALL, Sou5, ORANGETAIL, and ROOTRUN. SonicWall’s advisory names log paths and a config file. Both feed the same hunt: are those filenames, paths, or content patterns present on any appliance you own — patched or not?
  • The rebuild threshold is real. Any IoC hit on any of the four implants or the SonicWall-listed log/config entries means the appliance was compromised before it was patched. The patched build closes the vuln; it does not remove staged persistence. Rebuild — do not clean.
  • Credential rotation still stands. The command-injection half of the chain needs admin. If a session or credential from before the patch is still valid, the second half of the chain remains reachable through a patched appliance. Rotate everything that touched the box in the observed window.

Confidence summary

  • UTA0533 as tracked actor for the SMA1000 exploitation — single-vendor attribution (Volexity), no second-source corroboration yet.
  • June 22 earliest observed exploitation — as-observed by Volexity, not asserted as earliest-possible.
  • KNUCKLEBALL, Sou5, ORANGETAIL, ROOTRUN implant names and roles — as-reported by Volexity via BleepingComputer.
  • CVE IDs, CVSS scores, fixed builds, KEV status, federal deadline — confirmed against NVD, SNWLID-2026-0008, and CISA KEV.
  • Country nexus for UTA0533 — none publicly asserted at time of filing. Unconfirmed. Treat accordingly.

Prior filing: the July 14 KEV brief. Vendor context on same-week gateway patches: Progress ShareFile Storage Zone Controllers and Microsoft’s July Patch Tuesday. Related CVE stubs: CVE-2026-15409, CVE-2026-15410.

Sources

Related CVEs
  • [ CRITICAL ] CVE-2026-15409 SonicWall SMA1000 unauthenticated SSRF in Work Place portal
  • [ HIGH ] CVE-2026-15410 SonicWall SMA1000 post-authentication OS command injection

Found this useful? Share it.