SonicWall Zero-Days Sat Unpatched for Weeks While Hackers Quietly Planted Custom Malware
Two SonicWall vulnerabilities were being actively exploited for weeks before the company got patches out — which is exactly the kind of timeline that should make any security team nervous.
SonicWall published its advisory on July 14, confirming that CVE-2026-15409 and CVE-2026-15410 had already been used against customers in the wild. Both flaws affect SMA1000 secure remote access appliances and can be exploited remotely without any authentication. Hotfixes are now available.
Cybersecurity firm Volexity, which assisted SonicWall's investigation, says exploitation likely began around June 22 — giving attackers roughly three weeks of free rein. They've attributed the campaign to a threat actor they're calling UTA0533, though they haven't connected the group to any previously known operation. The motivation remains officially unclear, but the tradecraft Volexity describes — patient, targeted, using custom tooling — reads more like a state-backed operation than opportunistic ransomware crews hunting for quick payouts.
Once inside a compromised appliance, the attackers deployed a custom malware family called KnuckleBall. That then injected two further tools into legitimate running processes: OrangeTail, a bespoke Java webshell, and Suo5, an open-source proxy. Clean on the surface, messy underneath.
The access this kind of foothold provides is significant. As Volexity put it, root-level control over the appliance meant attackers could reach cached credentials, intercept network traffic, and potentially capture credentials flowing through the device. Not great for something that's supposed to be securing remote access.
There's a silver lining of sorts. Despite the sophistication of the initial compromise, Volexity found little evidence that UTA0533 made much headway moving laterally into connected systems. Whether that reflects operational caution, limited objectives, or simply being caught before they got comfortable is hard to say.
CISA has added both CVEs to its Known Exploited Vulnerabilities catalogue. That catalogue now lists 17 SonicWall flaws in total, which at this point is starting to feel less like a coincidence and more like a pattern worth paying attention to.
If you're running SMA1000 appliances, patch now and check Volexity's published indicators of compromise while you're at it.