KNUCKLEBALL is a Python-based malware loader used by the threat actor UTA0533 on compromised SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. It was observed in a campaign beginning in June 2026 in which attackers chained CVE-2026-15409 and CVE-2026-15410 to obtain unauthenticated root-level access before deploying an appliance-specific malware toolkit. Its targeted environment comprises Linux-based enterprise remote-access appliances, including physical and virtual SMA 1000 systems.
KNUCKLEBALL contains two embedded JAR payloads and uses the Java Attach API to inject malicious Java agents into a legitimate running SonicWall JVM. The injected components are a modified Suo5 HTTP proxy, which supports tunneling and internal-network pivoting, and ORANGETAIL, a custom Behinder-like Java webshell supporting command execution and file transfer. Hosting these implants inside a trusted application process provides memory-resident execution and helps conceal their activity.
The loader establishes persistence by modifying the appliance's application startup script so that it executes again after reboot. It also modifies NGINX Unit routing configuration to expose the implanted components through concealed web routes and suppresses Java-agent logging. KNUCKLEBALL serves as the deployment and persistence component of the toolkit rather than the credential-capture or privilege-escalation component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“CVE-2026-15409 — CVSS 10.0. A pre-authentication /wsproxy bypass allowing an unauthenticated external attacker to open a WebSocket tunnel to services intended to be accessible only from localhost.” The report states that UTA0533 chained this vulnerability with CVE-2026-15410 beginning June 22, 2026, before disclosure.
“CVE-2026-15410 — CVSS 7.2. A path-traversal flaw in the remove_hotfix workflow of ctrl-service, abused to escalate from a low-privilege service account to root.” Investigators reportedly recovered an encoded exploit at /tmp/hypdate.b64 on compromised appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KNUCKLEBALL is the primary malware loader responsible for deploying the remaining implants.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
attackers used the appliance's embedded CouchDB service — which ships with hard-coded default credentials — to stage a script and trigger the path-traversal flaw. This allowed root command execution without any valid SMA administrator credentials.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities to achieve root-level access on the devices before patches existed. UTA0533 had exploited to deploy a malicious Python script named KNUCKLEBALL.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader)
Deploy persistence: The attacker modifies startup scripts and configuration files to keep access after restart.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware reportedly deployed by UTA0533 through exploitation of the SonicWall SMA1000 vulnerability.
KNUCKLEBALL is mentioned only as malware associated with a separate, earlier July 2026 SonicWall SMA 1000 exploitation campaign.
A malicious Python script deployed by UTA0533 after the actor chained zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances to obtain root-level access.
Malware deployed by UTA0533 following exploitation of SonicWall SMA 1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410. The content provides no further functional or technical details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.