Volexity Details Zero-Day Exploitation of SonicWall SMA VPN Appliances

· Original article ↗

Summary

Volexity traced UTA0533’s compromise of SonicWall SMA 1000 appliances to two zero-days, detailing the exploit chain, malware, post-compromise activity, indicators, and available patches.

Key points

  • Volexity found two SonicWall SMA 1000 appliances compromised; evidence showed activity beginning June 22, 2026, and attributed it to tracked actor UTA0533.
  • CVE-2026-15409 enabled unauthenticated WebSocket access to localhost services through /wsproxy; CVE-2026-15410 allowed path traversal and command execution as root.
  • The attack chain used the appliances’ CouchDB service to stage a script, then exploited the control service to execute it with root privileges.
  • Malware included ROOTRUN, a setuid privilege-escalation tool, and KNUCKLEBALL, which injected the Suo5 proxy and ORANGETAIL webshell and established persistence.
  • After gaining access, the actor captured unencrypted LDAP traffic to obtain credentials and attempted to pivot to other network systems; Volexity found limited evidence of successful lateral movement.
  • SonicWall patched the vulnerabilities in versions 12.4.3-03453 and 12.5.0-02835; Volexity also published forensic indicators and YARA signatures.

Article Details

Attack Vectors
  • Unauthenticated requests to /wsproxy with User-Agent: SMA Connect Agent and a bmID beginning with -3389 established WebSocket tunnels to localhost-only appliance services through CVE-2026-15409.
  • The attacker used the appliance's CouchDB service to write and execute a script that read /sys/class/dmi/id/product_uuid. Volexity could not determine the exact CouchDB exploitation operation.
  • The appliance UUID supplied the information needed to derive the control-service authentication password and access sysCtrl.
  • Path traversal in sysCtrl.execRemoveHotfix caused the privileged remove_hotfix helper to execute an attacker-staged script outside the intended rollback directory, providing root-level command execution.
  • Injected Java agents replaced existing application classes with an HTTP forwarding proxy and a custom webshell. Modified nginx routes exposed these implants through external requests.
  • The attacker captured unencrypted LDAP traffic to extract usernames and passwords and attempted authentication to other systems from the compromised appliances.
Defensive Notes
  • SonicWall patched the reported vulnerabilities in appliance versions 12.4.3-03453 and 12.5.0-02835. The affected SMA 1000 series models listed in the article are 6210, 7210, and 8200v.
  • Inspect /var/log/aventail/extraweb_access.log for /wsproxy requests with bmID values beginning with -3389, internal-service destinations, ports 1050 or 8188, and HTTP status 101.
  • Review successful requests to unexpected endpoints, including /__api__/login and /__api__/logout, and inspect /var/log/aventail/access_servers.log for suspicious WebSocket connections.
  • Inspect /var/log/aventail/ctrl-service.log for hotfix-removal requests containing traversal paths such as ../../../../../tmp/1234.sh.
  • Monitor unexpected outbound and lateral connections originating from appliances.
  • Inspect /tmp and /var/tmp for unexpected files, scripts, and packet captures, and investigate unexpected system-file modifications.
  • Review /var/lib/unit/conf.json for unexpected proxy routes and inspect /etc/init.d/workplace for unauthorized startup commands.
  • Use find / -perm -4000 to identify unexpected setuid binaries, accounting for the legitimate binaries listed in the article.
  • Volexity released YARA signatures for the discovered malware families.
  • Volexity assessed that a reboot likely removed memory-resident backdoors and potentially other volatile evidence from the second appliance; inactive implants at collection did not negate other compromise evidence.

Indicators of compromise

TypeIndicatorContext
IPV4108[.]205[.]8[.]173Non-VPN source IP identified by Volexity as used in the attacks.
IPV4147[.]45[.]51[.]19Non-VPN source IP identified by Volexity as used in the attacks.
IPV4150[.]241[.]210[.]53Non-VPN source IP identified by Volexity as used in the attacks.
IPV4202[.]8[.]105[.]201Non-VPN source IP identified by Volexity as used in the attacks.
IPV4217[.]77[.]15[.]99Non-VPN source IP identified by Volexity as used in the attacks.
IPV442[.]200[.]172[.]14Non-VPN source IP identified by Volexity as used in the attacks.
IPV481[.]19[.]140[.]217Non-VPN source IP identified by Volexity as used in the attacks.
IPV489[.]117[.]20[.]1Non-VPN source IP identified by Volexity as used in the attacks.
MD554d21399b8b52b48a0fef68450593e45Source-listed MD5 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance.
MD55cb00bbfe818ee3e85fb99ab1db1af7cSource-listed MD5 of the malicious xzfind executable identified as ROOTRUN.
MD55f3a55201c511c9ff9be4c16c41028a2Source-listed MD5 of agent_wp9.jar, the ORANGETAIL webshell payload.
MD5b6df166291f80ee89032d769c99714f3Source-listed MD5 of deploy_new.py, the KNUCKLEBALL implant loader.
SHA104d4a9fbb32e967200eb98be014ca914a03bfa6bSource-listed SHA1 of the malicious xzfind executable identified as ROOTRUN.
SHA15e5b716f2385c818ec61198be1a2a07a4560eac5Source-listed SHA1 of agent_wp9.jar, the ORANGETAIL webshell payload.
SHA1b4ee1f50fbb49f0ff5fde3d026343bc23ee08d51Source-listed SHA1 of deploy_new.py, the KNUCKLEBALL implant loader.
SHA1c2b0ae0a1f42a139abe4dd612676066ec1426394Source-listed SHA1 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance.
SHA2561e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edeeSource-listed SHA256 of agent_wp8.jar, the modified Suo5 proxy payload injected into the appliance.
SHA25681a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2Source-listed SHA256 of the malicious xzfind executable identified as ROOTRUN.
SHA2568c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3Source-listed SHA256 of deploy_new.py, the KNUCKLEBALL implant loader.
SHA256ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081Source-listed SHA256 of agent_wp9.jar, the ORANGETAIL webshell payload.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationKNUCKLEBALL embedded Base64-encoded JAR payloads, while ORANGETAIL constructed sensitive strings character by character.T1037.004 · RC ScriptsThe attacker added a command to /etc/init.d/workplace to execute deploy_new.py during application startup.T1040 · Network SniffingUTA0533 used tcpdump to capture unencrypted LDAP traffic and extract usernames and passwords.T1055 · Process InjectionKNUCKLEBALL used the Java Attach API to inject instrumentation agents into the running workplace.startup.CommandStartup JVM.T1057 · Process DiscoveryKNUCKLEBALL enumerated command-line pseudo-files under /proc to locate the target JVM process.T1059.004 · Unix ShellROOTRUN executes supplied commands through bash, and attacker shell scripts were used for exploitation and packet capture.T1059.006 · PythonThe attacker executed deploy_new.py to load embedded Java agents and configure access to the implants.T1068 · Exploitation for Privilege EscalationThe attacker abused sysCtrl.execRemoveHotfix path traversal to execute an attacker-staged script as root.T1070.002 · Clear Linux or Mac System LogsKNUCKLEBALL cleared the Java agents' log files before injection and linked their paths to /dev/null to prevent retained logs.T1070.004 · File DeletionKNUCKLEBALL deleted both temporarily written JAR files after injecting their agents.T1090.001 · Internal ProxyThe attacker used the injected Suo5 HTTP forwarding proxy while attempting to pivot from the compromised appliance into the customer network.T1090.002 · External ProxySome exploitation and webshell requests originated from ExpressVPN and MullvadVPN addresses, placing external VPN services between the attacker and appliances.T1140 · Deobfuscate/Decode Files or InformationKNUCKLEBALL decoded embedded JAR payloads, and ORANGETAIL decoded and decrypted attacker-supplied Java classes before loading them.T1190 · Exploit Public-Facing ApplicationUTA0533 exploited the externally reachable SMA /wsproxy endpoint to tunnel unauthenticated requests to localhost-only services.T1505.003 · Web ShellORANGETAIL replaced an existing Java application class with a webshell accepting encrypted payloads through HTTP POST requests.T1548.001 · Setuid and SetgidThe attacker installed the setuid xzfind binary, identified as ROOTRUN, to let an unprivileged user execute commands as root.T1573.001 · Symmetric CryptographyORANGETAIL encrypted incoming payloads and outgoing responses with AES-128-ECB using a hardcoded key.

CVE

Threat Actors

Malware

Vendors

Products

Tools

Related Articles