UNC4540 is an uncategorized threat actor tracked by Mandiant for compromises of unpatched SonicWall Secure Mobile Access (SMA) 100 Series appliances, with activity dating to at least 2021. Its operations involve appliance-specific malware designed to steal user credentials, provide remote shell access, and maintain long-term persistence. No additional aliases or subgroups are established. The actor's tooling combines Bash scripts with a TinyShell ELF backdoor supporting reverse-shell and bind-shell access. The malware queries the appliance's session database to extract usernames and hashed passwords belonging to logged-in users. Redundant scripts monitor and restart malware components, while boot-time execution mechanisms preserve access across restarts. A firmware-monitoring component modifies incoming firmware packages before installation, embedding the malware and adding a privileged backdoor account so access survives firmware upgrades. This modification occurs on already compromised appliances rather than through a software supply-chain compromise. The initial compromise vector has not been established. Although affected appliances had known vulnerabilities, no specific vulnerability has been conclusively linked to the campaign. The actor's geographic origin and state sponsorship remain unconfirmed, and no high-confidence connection to ransomware activity has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted SonicWall Secure Mobile Access (SMA) appliances, deploying custom malware designed to persist even after firmware upgrades (suggesting a focus on durable access to edge devices for follow-on operations).
Targeting unpatched SonicWall SMA appliances to install custom malware for long-term persistence, credential theft, reverse shell access, and cyber espionage.
UNC4540 conducts suspected cyberespionage against SonicWall SMA 100 Series VPN appliances, with activity dating to at least 2021. Its malware steals logged-in users' hashed credentials and maintains persistent access across crashes and firmware upgrades. Mandiant suggests Chinese state backing based on the campaign's characteristics, but attribution remains tentative. The initial intrusion vector and any connection to earlier ransomware attacks are unconfirmed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.