ORANGETAIL is a custom, memory-resident Java web shell modeled after Behinder 3.x and deployed on Linux-based SonicWall Secure Mobile Access (SMA) 1000 VPN appliances. It executes attacker-supplied Java payloads and supports command execution and file transfer. Its communications use Base64-encoded AES-128-ECB encryption with a hardcoded key. The implant responds only to requests containing a specific fabricated browser User-Agent and returns a normal-looking HTTP 404 response when that condition is not met, concealing its presence from ordinary requests.
ORANGETAIL was deployed by the threat cluster UTA0533 during intrusions beginning in June 2026. Attackers chained CVE-2026-15409 and CVE-2026-15410 to obtain root access on exposed SMA 1000 appliances before installing their malware toolkit. The Python loader KNUCKLEBALL injected ORANGETAIL and the Suo5 HTTP proxy into a legitimate SonicWall Java process through the Java Attach API. Modified web-routing configuration exposed the implants through concealed access routes, while startup-script changes relaunched the loader after reboot. ORANGETAIL provided post-exploitation access and was used alongside Suo5 in attempts to pivot into internal networks. Associated tooling included the ROOTRUN privileged-execution backdoor; credential interception and traffic capture observed in these intrusions were performed using separate tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances.
In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ORANGETAIL is a custom Java memory-resident web shell modeled after Behinder 3.x.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
Host a persistent, appliance-specific webshell that survives casual inspection... Malware File... ORANGETAIL (webshell) agent_wp9.jar
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on compromised SonicWall SMA1000 appliances during July 2026 zero-day exploitation. The content does not describe its capabilities or connect it to the current October exploitation attempts.
Custom malware installed on vulnerable SonicWall SMA1000 VPN appliances during earlier zero-day attacks. Its capabilities are not described; it is mentioned as historical background, not linked to the current CVE-2026-102255 exploitation attempts.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
Custom Behinder-like Java web shell used in the SonicWall SMA exploitation campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.