UTA0533 is an unattributed threat actor tracked by Volexity for compromising SonicWall Secure Mobile Access (SMA) 1000 VPN appliances beginning at least June 22, 2026. The actor exploited CVE-2026-15409 and CVE-2026-15410 before their public disclosure and patch release on July 14, 2026. Its country of origin, organizational affiliation, and motivation have not been established, and it has not been conclusively linked to another named threat group. UTA0533 chained an unauthenticated server-side request forgery vulnerability with a path-traversal vulnerability in the appliance's privileged hotfix-removal workflow. This enabled access to localhost-only services, command execution, and escalation to root without valid VPN credentials or user interaction. The actor deployed appliance-specific tooling, including ROOTRUN, a setuid backdoor providing root command execution, and KNUCKLEBALL, a Python loader that injected Java payloads into a legitimate SonicWall process. These payloads included a modified Suo5 HTTP proxy for tunneling and internal pivoting and ORANGETAIL, a custom, memory-resident Java web shell resembling Behinder. Persistence involved modifications to appliance startup scripts and NGINX Unit routing configuration. Memory-resident implants, encrypted web-shell communications, and request-header gating supported covert access. UTA0533 also used packet capture to harvest credentials from unencrypted LDAP traffic and attempted lateral movement into victim networks, although observed success beyond the compromised appliances was limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
“CVE-2026-15409 — CVSS 10.0. A pre-authentication /wsproxy bypass allowing an unauthenticated external attacker to open a WebSocket tunnel to services intended to be accessible only from localhost.” The report states that UTA0533 chained this vulnerability with CVE-2026-15410 beginning June 22, 2026, before disclosure.
“CVE-2026-15410 — CVSS 7.2. A path-traversal flaw in the remove_hotfix workflow of ctrl-service, abused to escalate from a low-privilege service account to root.” Investigators reportedly recovered an encoded exploit at /tmp/hypdate.b64 on compromised appliances.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used CVE-2026-15409 to deploy KNUCKLEBALL malware.
Exploited separate SonicWall SMA 1000 zero-day vulnerabilities in an earlier July 2026 campaign associated with KNUCKLEBALL malware. The content does not establish a link between UTA0533 and the active exploitation of CVE-2026-83548 and CVE-2026-83549.
Exploited a chain of two then-zero-day vulnerabilities against SonicWall SMA 1000 VPN appliances to gain root-level access and deploy the malicious Python script KNUCKLEBALL.
Previously exploited CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA 1000 appliances to deploy KNUCKLEBALL malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.