ROOTRUN is a Linux ELF privilege-escalation utility used in intrusions against SonicWall SMA 1000 series secure remote access appliances. It has been observed in exploitation chains involving CVE-2026-15409 and CVE-2026-15410, where attackers obtained root-level access on vulnerable VPN gateways and then deployed a tailored post-exploitation toolkit that included ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL. Investigations linked this activity to the threat actor UTA0533, with reporting also noting overlap with operations associated with INC Ransomware.
ROOTRUN is a malicious setuid binary that allows an unprivileged user to execute arbitrary commands with root privileges, effectively providing durable privileged execution on a compromised appliance. It has been characterized as a persistent root-execution backdoor and privilege-escalation tool. In observed compromises, attackers used it after initial exploitation to maintain reliable root command execution even if their original exploit path was no longer needed.
The malware was deployed on SonicWall SMA 1000 appliances after unauthenticated exploitation of the exposed management and workplace components. Post-compromise activity associated with the same campaigns included persistence through startup-script and routing-configuration changes, covert proxying via Suo5, memory-resident web-shell access via ORANGETAIL, credential-harvesting opportunities through packet capture of unencrypted LDAP traffic, and attempts to pivot from the appliance into internal enterprise networks. The targeted systems were enterprise VPN appliances that sit at a sensitive trust boundary, making ROOTRUN particularly significant as an enabler of long-term privileged access and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. While SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain allowed the threat actor to compromise vulnerable SonicWall SMA VPN appliances, access localhost-only services, execute commands, escalate privileges, deploy malware, modify configuration files, and gain root-level access.
The second can turn a low-privilege foothold into root control by causing a staged script to run with full system rights.
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
altered startup and routing settings helped implants survive restarts
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
A malicious setuid binary deployed after root compromise to provide privileged execution and persistence on compromised SonicWall SMA appliances.
A malicious setuid binary deployed after appliance compromise to provide root-level execution and persistence on affected SonicWall SMA appliances.
A malicious setuid ELF binary installed after root compromise that allows unprivileged users to execute arbitrary commands as root, providing durable local privilege escalation and persistent backdoor access on compromised SonicWall SMA appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.