← BACK TO FEED
SonicWallzero-dayAPTmalwarevulnerability

SonicWall Zero-Days Sat Unpatched for Weeks While Hackers Quietly Planted Custom Malware

Two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in SMA1000 appliances were exploited by a threat actor tracked as UTA0533 for several weeks before patches were released in July, with attacks beginning as early as June 22. The attackers deployed custom malware called KnuckleBall, which injected a Java webshell and an open-source proxy into legitimate processes, granting root access to credentials and network traffic. While SonicWall has since issued hotfixes and CISA has added the flaws to its Known Exploited Vulnerabilities catalog, the group's identity and motivation remain unclear, though the attack's sophistication suggests possible state-sponsored activity.

Two SonicWall vulnerabilities were being actively exploited for weeks before the company got patches out — which is exactly the kind of timeline that should make any security team nervous.

SonicWall published its advisory on July 14, confirming that CVE-2026-15409 and CVE-2026-15410 had already been used against customers in the wild. Both flaws affect SMA1000 secure remote access appliances and can be exploited remotely without any authentication. Hotfixes are now available.

Cybersecurity firm Volexity, which assisted SonicWall's investigation, says exploitation likely began around June 22 — giving attackers roughly three weeks of free rein. They've attributed the campaign to a threat actor they're calling UTA0533, though they haven't connected the group to any previously known operation. The motivation remains officially unclear, but the tradecraft Volexity describes — patient, targeted, using custom tooling — reads more like a state-backed operation than opportunistic ransomware crews hunting for quick payouts.

Once inside a compromised appliance, the attackers deployed a custom malware family called KnuckleBall. That then injected two further tools into legitimate running processes: OrangeTail, a bespoke Java webshell, and Suo5, an open-source proxy. Clean on the surface, messy underneath.

The access this kind of foothold provides is significant. As Volexity put it, root-level control over the appliance meant attackers could reach cached credentials, intercept network traffic, and potentially capture credentials flowing through the device. Not great for something that's supposed to be securing remote access.

There's a silver lining of sorts. Despite the sophistication of the initial compromise, Volexity found little evidence that UTA0533 made much headway moving laterally into connected systems. Whether that reflects operational caution, limited objectives, or simply being caught before they got comfortable is hard to say.

CISA has added both CVEs to its Known Exploited Vulnerabilities catalogue. That catalogue now lists 17 SonicWall flaws in total, which at this point is starting to feel less like a coincidence and more like a pattern worth paying attention to.

If you're running SMA1000 appliances, patch now and check Volexity's published indicators of compromise while you're at it.

WATCH THE SHORT
READ NEXT
New Backdoors OctLurk and SilkLurk Linked to Chinese-Speaking Hackers Hitting Central Asian GovernmentsShareFile Shutdown Orders, Citrix Bleed 2 Ransomware, and AI Coding Assistants You Can't TrustUnknown Threat Actor Chained SonicWall Zero-Days to Root Before Anyone Knew They Existed