KNUCKLEBALL is a Python-based malware loader used in intrusions targeting SonicWall SMA 1000 series secure remote access appliances. It has been associated with threat activity tracked as UTA0533 and has also been observed in campaigns overlapping with ransomware operations, including activity linked by reporting to INC Ransomware. The malware was deployed after attackers obtained root-level access on vulnerable appliances by exploiting the SonicWall SMA 1000 vulnerability chain involving CVE-2026-15409 and CVE-2026-15410.
KNUCKLEBALL serves as the primary in-memory deployment mechanism for additional implants rather than acting as a standalone payload. Its core function is to inject embedded Java components into a legitimate SonicWall Java process using the Java Attach API, allowing the attacker to hide malicious functionality inside trusted appliance processes. The injected payloads have included Suo5, an HTTP proxy and forwarding tool used for covert tunneling and pivoting, and ORANGETAIL, a custom memory-resident Java web shell modeled on Behinder-like tradecraft. This design supports stealth, post-compromise access, and operational flexibility on the appliance.
The malware has also been used to establish persistence on compromised devices by modifying startup behavior so the loader is re-executed after reboot. In observed incidents, attackers additionally altered appliance web-routing and service configuration to expose hidden access paths to the injected implants while blending with legitimate application behavior. These changes enabled durable covert access and supported follow-on actions such as credential interception, traffic monitoring, and attempted movement deeper into victim environments.
KNUCKLEBALL has been observed on Linux-based SonicWall SMA 1000 appliances, including physical and virtual deployments in the affected product line. Its role in the intrusion lifecycle is post-exploitation: it is deployed only after successful compromise and is used to load and maintain secondary tooling for proxying, web-shell access, and persistence on the appliance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks. While SonicWall has yet to update its original advisory to confirm that CVE-2026-15409 and CVE-2026-15410 are targeted in ransomware attacks, CISA has now also flagged them as exploited by ransomware gangs in recent updates to the KEV Catalog. | Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 ... to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used it to write and run a script that read the hardware ID file... From there they exploited the second bug... They did it via a booby-trapped file path that let them execute their own script with the highest level of privilege on the device.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader)
Deploy persistence: The attacker modifies startup scripts and configuration files to keep access after restart.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy
The first embedded JAR file was the open-source HTTP proxy-forwarding tool Suo5.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
A Python loader used to inject malicious Java agents onto compromised SonicWall SMA appliances.
A Python loader used to inject malicious Java agents onto compromised SonicWall SMA appliances.
A Python loader that decodes embedded JAR payloads, writes them to /tmp, injects them into the SonicWall Workplace JVM via the Java Attach API, clears traces, and establishes persistence by modifying init scripts and NGINX Unit configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.