ORANGETAIL is a custom Java memory-resident web shell used in intrusions against SonicWall SMA 1000 series secure remote access appliances. It is modeled after the Behinder framework, particularly Behinder 3.x–style tradecraft, and was observed as part of a broader post-exploitation toolkit that also included KNUCKLEBALL, Suo5, and ROOTRUN. The malware was associated with activity tracked as UTA0533 and later reporting linked overlapping operations to exploitation campaigns that became heavily used by INC Ransomware.
ORANGETAIL was deployed after attackers chained CVE-2026-15409 and CVE-2026-15410 to obtain root access on vulnerable SMA 1000 appliances. KNUCKLEBALL, a Python-based loader, injected ORANGETAIL into a legitimate SonicWall Java process using the Java Attach API, allowing the web shell to remain memory-resident and blend into trusted appliance components. The attackers also modified startup and web-routing configuration to preserve access across reboots and to expose covert access paths through the appliance’s web application stack.
Functionally, ORANGETAIL acts as a covert remote-access web shell that executes Java payloads supplied by the operator. It was designed to be stealthy: it only responded to requests carrying a specific spoofed or slightly malformed browser identification string, and otherwise could present benign-looking behavior. Reporting also describes encrypted operator communications consistent with Behinder-style web shell operation. In the observed campaigns, ORANGETAIL was used alongside Suo5, an HTTP proxy and tunneling component, enabling the compromised appliance to serve as a pivot point for post-exploitation activity.
Compromise of SMA 1000 appliances with ORANGETAIL provided attackers with a high-value foothold on enterprise VPN infrastructure. Investigators assessed that such access enabled credential theft opportunities, interception of traffic traversing the appliance, persistence on the gateway, and attempted lateral movement into internal networks. Observed follow-on activity in the same intrusions included packet capture of unencrypted LDAP traffic to harvest credentials. The malware targeted Linux-based SonicWall SMA 1000 appliances, including physical and virtual deployments in that product line.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. While SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader)
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
Custom Behinder-like Java web shell used in the SonicWall SMA exploitation campaign.
A memory-resident Java web shell agent used on compromised SonicWall SMA appliances for covert remote access and command execution.
A memory-resident Java web shell agent used on compromised SonicWall SMA appliances for covert access and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.