SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
SonicWall appliances were targeted by threat actors exploiting two unpatched zero-days for weeks before a fix was released. The attackers, tracked as UTA0533, deployed custom malware – KnuckleBall, OrangeTail, and Suo5 – to gain access and potentially steal credentials. The incident suggests a sophisticated, possibly state-sponsored, attack.
Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before a fix was released. SonicWall released a public advisory on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild. Remote, unauthenticated attackers could exploit these flaws to hack SMA1000 secure remote access appliances. SonicWall has made available hotfix releases to address the security holes.
Volexity, which assisted the vendor’s investigation into the attacks, attributed the exploitation of the zero-days to a threat actor it tracks as UTA0533. The security firm believes exploitation started as early as June 22.
Once the attackers compromised the targeted SonicWall appliances, they deployed custom malware named KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail, and an open source proxy named Suo5. Volexity stated that with root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
CISA has added CVE-2026-15409 and CVE-2026-15410 to its KEV catalog. The security firm added that although UTA0533 demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests the threat actor was less successful moving laterally or gaining access to other systems.