ROOTRUN is a Linux ELF setuid backdoor and privilege-escalation utility deployed on compromised SonicWall Secure Mobile Access (SMA) 1000 VPN appliances. Installed after attackers obtain root access, it allows an unprivileged local user to execute arbitrary commands with root privileges. The utility uses setuid() to elevate its execution context and runs attacker-supplied commands through Bash, providing a persistent means of regaining privileged execution on the appliance.
ROOTRUN was deployed by the threat actor tracked as UTA0533 in intrusions observed from June 22, 2026. The actor chained CVE-2026-15409, a pre-authentication server-side request forgery vulnerability exposing localhost-only services, with CVE-2026-15410, a path-traversal and privileged command-execution vulnerability, to obtain root access before installing the utility. ROOTRUN appeared alongside KNUCKLEBALL, Suo5, and ORANGETAIL in an appliance-focused post-exploitation toolkit. Its established function is privileged command execution; proxying, Java payload injection, and web-shell functionality are provided by the accompanying tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances.
In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ROOTRUN is a malicious setuid ELF binary (internally named rootrun) installed after root compromise.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
The attack chain allowed the threat actor to compromise vulnerable SonicWall SMA VPN appliances, access localhost-only services, execute commands, escalate privileges, deploy malware, modify configuration files, and gain root-level access.
The second can turn a low-privilege foothold into root control by causing a staged script to run with full system rights.
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
altered startup and routing settings helped implants survive restarts
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on compromised SonicWall SMA1000 appliances during July 2026 zero-day exploitation. The content does not describe its capabilities or connect it to the current October exploitation attempts.
Custom malware installed on vulnerable SonicWall SMA1000 VPN appliances during earlier zero-day attacks. Its capabilities are not described; it is mentioned as historical background, not linked to the current CVE-2026-102255 exploitation attempts.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
A malicious setuid binary deployed after root compromise to provide privileged execution and persistence on compromised SonicWall SMA appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.