Volexity Details Zero-Day Exploitation of SonicWall SMA VPN Appliances

Summary
Volexity traced UTA0533’s compromise of SonicWall SMA 1000 appliances to two zero-days, detailing the exploit chain, malware, post-compromise activity, indicators, and available patches.
Key points
- Volexity found two SonicWall SMA 1000 appliances compromised; evidence showed activity beginning June 22, 2026, and attributed it to tracked actor UTA0533.
- CVE-2026-15409 enabled unauthenticated WebSocket access to localhost services through /wsproxy; CVE-2026-15410 allowed path traversal and command execution as root.
- The attack chain used the appliances’ CouchDB service to stage a script, then exploited the control service to execute it with root privileges.
- Malware included ROOTRUN, a setuid privilege-escalation tool, and KNUCKLEBALL, which injected the Suo5 proxy and ORANGETAIL webshell and established persistence.
- After gaining access, the actor captured unencrypted LDAP traffic to obtain credentials and attempted to pivot to other network systems; Volexity found limited evidence of successful lateral movement.
- SonicWall patched the vulnerabilities in versions 12.4.3-03453 and 12.5.0-02835; Volexity also published forensic indicators and YARA signatures.
Article Details
- Attack Vectors
- Unauthenticated requests to /wsproxy with User-Agent: SMA Connect Agent and a bmID beginning with -3389 established WebSocket tunnels to localhost-only appliance services through CVE-2026-15409.
- The attacker used the appliance's CouchDB service to write and execute a script that read /sys/class/dmi/id/product_uuid. Volexity could not determine the exact CouchDB exploitation operation.
- The appliance UUID supplied the information needed to derive the control-service authentication password and access sysCtrl.
- Path traversal in sysCtrl.execRemoveHotfix caused the privileged remove_hotfix helper to execute an attacker-staged script outside the intended rollback directory, providing root-level command execution.
- Injected Java agents replaced existing application classes with an HTTP forwarding proxy and a custom webshell. Modified nginx routes exposed these implants through external requests.
- The attacker captured unencrypted LDAP traffic to extract usernames and passwords and attempted authentication to other systems from the compromised appliances.
- Defensive Notes
- SonicWall patched the reported vulnerabilities in appliance versions 12.4.3-03453 and 12.5.0-02835. The affected SMA 1000 series models listed in the article are 6210, 7210, and 8200v.
- Inspect /var/log/aventail/extraweb_access.log for /wsproxy requests with bmID values beginning with -3389, internal-service destinations, ports 1050 or 8188, and HTTP status 101.
- Review successful requests to unexpected endpoints, including /__api__/login and /__api__/logout, and inspect /var/log/aventail/access_servers.log for suspicious WebSocket connections.
- Inspect /var/log/aventail/ctrl-service.log for hotfix-removal requests containing traversal paths such as ../../../../../tmp/1234.sh.
- Monitor unexpected outbound and lateral connections originating from appliances.
- Inspect /tmp and /var/tmp for unexpected files, scripts, and packet captures, and investigate unexpected system-file modifications.
- Review /var/lib/unit/conf.json for unexpected proxy routes and inspect /etc/init.d/workplace for unauthorized startup commands.
- Use find / -perm -4000 to identify unexpected setuid binaries, accounting for the legitimate binaries listed in the article.
- Volexity released YARA signatures for the discovered malware families.
- Volexity assessed that a reboot likely removed memory-resident backdoors and potentially other volatile evidence from the second appliance; inactive implants at collection did not negate other compromise evidence.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 108[.]205[.]8[.]173 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 147[.]45[.]51[.]19 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 150[.]241[.]210[.]53 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 202[.]8[.]105[.]201 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 217[.]77[.]15[.]99 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 42[.]200[.]172[.]14 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 81[.]19[.]140[.]217 | Non-VPN source IP identified by Volexity as used in the attacks. |
| IPV4 | 89[.]117[.]20[.]1 | Non-VPN source IP identified by Volexity as used in the attacks. |
| MD5 | 54d21399b8b52b48a0fef68450593e45 | Source-listed MD5 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance. |
| MD5 | 5cb00bbfe818ee3e85fb99ab1db1af7c | Source-listed MD5 of the malicious xzfind executable identified as ROOTRUN. |
| MD5 | 5f3a55201c511c9ff9be4c16c41028a2 | Source-listed MD5 of agent_wp9.jar, the ORANGETAIL webshell payload. |
| MD5 | b6df166291f80ee89032d769c99714f3 | Source-listed MD5 of deploy_new.py, the KNUCKLEBALL implant loader. |
| SHA1 | 04d4a9fbb32e967200eb98be014ca914a03bfa6b | Source-listed SHA1 of the malicious xzfind executable identified as ROOTRUN. |
| SHA1 | 5e5b716f2385c818ec61198be1a2a07a4560eac5 | Source-listed SHA1 of agent_wp9.jar, the ORANGETAIL webshell payload. |
| SHA1 | b4ee1f50fbb49f0ff5fde3d026343bc23ee08d51 | Source-listed SHA1 of deploy_new.py, the KNUCKLEBALL implant loader. |
| SHA1 | c2b0ae0a1f42a139abe4dd612676066ec1426394 | Source-listed SHA1 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance. |
| SHA256 | 1e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edee | Source-listed SHA256 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance. |
| SHA256 | 81a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2 | Source-listed SHA256 of the malicious xzfind executable identified as ROOTRUN. |
| SHA256 | 8c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3 | Source-listed SHA256 of deploy_new.py, the KNUCKLEBALL implant loader. |
| SHA256 | ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081 | Source-listed SHA256 of agent_wp9.jar, the ORANGETAIL webshell payload. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationKNUCKLEBALL embedded Base64-encoded JAR payloads, while ORANGETAIL constructed sensitive strings character by character.T1037.004 · RC ScriptsThe attacker added a command to /etc/init.d/workplace to execute deploy_new.py during application startup.T1040 · Network SniffingUTA0533 used tcpdump to capture unencrypted LDAP traffic and extract usernames and passwords.T1055 · Process InjectionKNUCKLEBALL used the Java Attach API to inject instrumentation agents into the running workplace.startup.CommandStartup JVM.T1057 · Process DiscoveryKNUCKLEBALL enumerated command-line pseudo-files under /proc to locate the target JVM process.T1059.004 · Unix ShellROOTRUN executes supplied commands through bash, and attacker shell scripts were used for exploitation and packet capture.T1059.006 · PythonThe attacker executed deploy_new.py to load embedded Java agents and configure access to the implants.T1068 · Exploitation for Privilege EscalationThe attacker abused sysCtrl.execRemoveHotfix path traversal to execute an attacker-staged script as root.T1070.002 · Clear Linux or Mac System LogsKNUCKLEBALL cleared the Java agents' log files before injection and linked their paths to /dev/null to prevent retained logs.T1070.004 · File DeletionKNUCKLEBALL deleted both temporarily written JAR files after injecting their agents.T1090.001 · Internal ProxyThe attacker used the injected Suo5 HTTP forwarding proxy while attempting to pivot from the compromised appliance into the customer network.T1090.002 · External ProxySome exploitation and webshell requests originated from ExpressVPN and MullvadVPN addresses, placing external VPN services between the attacker and appliances.T1140 · Deobfuscate/Decode Files or InformationKNUCKLEBALL decoded embedded JAR payloads, and ORANGETAIL decoded and decrypted attacker-supplied Java classes before loading them.T1190 · Exploit Public-Facing ApplicationUTA0533 exploited the externally reachable SMA /wsproxy endpoint to tunnel unauthenticated requests to localhost-only services.T1505.003 · Web ShellORANGETAIL replaced an existing Java application class with a webshell accepting encrypted payloads through HTTP POST requests.T1548.001 · Setuid and SetgidThe attacker installed the setuid xzfind binary, identified as ROOTRUN, to let an unprivileged user execute commands as root.T1573.001 · Symmetric CryptographyORANGETAIL encrypted incoming payloads and outgoing responses with AES-128-ECB using a hardcoded key.
CVE
Threat Actors
UTA0533Volexity tracks the actor responsible for the SMA compromises under this name. The earliest observed compromise was June 22, 2026; activity included zero-day exploitation, implant deployment, LDAP credential capture, and attempted lateral movement.UTA0553The CouchDB exploitation section uses this identifier when stating that the exact exploitation operation remains unknown. The article otherwise attributes the intrusion to UTA0533 and does not explicitly establish a relationship between the two identifiers.
Malware
KNUCKLEBALLThis malware script, which Volexity calls KNUCKLEBALL, contained two embedded JAR archives that were injected into a legitimate SonicWall process.OrangeTailThe second was a Behinder-like webshell that Volexity calls ORANGETAIL.RootRunThe file was a setuid binary named rootrun that allowed an unprivileged user to execute arbitrary commands as root.
Vendors
ExpressVPNSeveral of the IP addresses were found to belong to ExpressVPN and MullvadVPN, based on lookups using Spur.MullvadVPNSeveral of the IP addresses were found to belong to ExpressVPN and MullvadVPN, based on lookups using Spur.SonicWallan incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices.VolexityIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain
Products
CouchDB127.0.0.1:1050 CouchDB Erlang distributionNGINX UnitThe NGINX Unit configuration file at /var/lib/unit/conf.json had been modified to add two routes leading to Suo5 and ORANGETAIL.SonicWall Secure Mobile Accessresponse investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices.
Tools
BehinderThe second was a Behinder-like webshell that Volexity calls ORANGETAIL.SpurSeveral of the IP addresses were found to belong to ExpressVPN and MullvadVPN, based on lookups using Spur.suo5The first embedded JAR file was the open-source HTTP proxy-forwarding tool Suo5.tcpdumpThese files were associated with using tcpdump to capture unencrypted LDAP traffic.Volexity Surge Collect ProUsing SSH access to the devices, Volexity collected system memory (RAM) with Volexity Surge Collect Pro, and gathered select files and full disk images.Volexity VolcanoThe memory sample was then further analyzed with Volexity Volcano.