Threat Actor
UTA0533
- First Reported
- Jul 17, 2026
- Latest Reported
- Jul 17, 2026
Reported Context (1)
- Volexity tracks the actor responsible for the SMA compromises under this name. The earliest observed compromise was June 22, 2026; activity included zero-day exploitation, implant deployment, LDAP credential capture, and attempted lateral movement. Volexity Details Zero-Day Exploitation of SonicWall SMA VPN Appliances
CVE (3)
Malware (3)
Threat Actors (1)
MITRE ATT&CK (17)
Vendors (4)
Products (3)
Tools (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.