Cybersecurity researchers have uncovered a previously undocumented threat actor that exploited two zero day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances before the flaws were publicly disclosed. Cybersecurity company Volexity, which tracks the activity under the name UTA0533, said the attacks began as early as June 22, 2026. The campaign came to light during an incident response investigation conducted earlier this month involving an unidentified organization. According to Volexity, the threat actor combined multiple zero day exploits with custom malware developed specifically for SonicWall SMA appliances, allowing the attackers to gain root level access and establish long term persistence on compromised systems. SonicWall has since released patches for the vulnerabilities, identified as CVE-2026-15409 with a CVSS score of 10.0 and CVE-2026-15410 with a CVSS score of 7.2.
The investigation identified two compromised SonicWall SMA VPN appliances at the affected organization. On the first appliance, the attackers deployed an ELF executable named xzfind, which functioned as a setuid binary called ROOTRUN and enabled unprivileged users to execute commands with root privileges. The attackers also placed a Python file named deploy_new.py that contained embedded Java archive files used to inject malicious code into a legitimate SonicWall process. These payloads included the open source HTTP proxy Suo5 and a custom Behinder style Java web shell known as ORANGETAIL, both of which enabled remote interaction through internet accessible URI paths. The attackers then modified legitimate startup scripts and changed the NGINX Unit configuration to maintain persistence and route requests to the malicious components. On the second appliance, researchers found similar configuration changes along with scripts that launched tcpdump to monitor unencrypted LDAP traffic in an attempt to capture usernames and passwords. However, a reboot on July 2, 2026, removed several memory resident artifacts and backdoors, leaving behind fewer traces of the compromise.
Further analysis revealed additional files in the temporary directory that were linked to exploitation and privilege escalation. One file contained exploit code for CVE-2026-15410, while log and memory analysis exposed CVE-2026-15409 as a pre authentication wsproxy bypass that allowed unauthenticated attackers to establish a WebSocket tunnel to services accessible only through localhost. By sending specially crafted requests using the SMA Connect Agent user agent and a bmID value beginning with negative 3389, attackers could reach internal services and eventually exploit command injection, privilege escalation, and code execution flaws within the SMA control service. Researchers also identified another authentication weakness involving the appliance product UUID, which could be used to derive the password for the SMA control service on physical devices. Although Volexity stated this authentication bypass was not used during the observed incident, the attackers were able to exploit another vulnerability to read the product UUID file before escalating privileges. Rapid7 noted that this technique allows attackers to reach internal services such as CouchDB and the SMA control service, enabling file operations and remote code execution through the established WebSocket tunnel.
According to Volexity, the complete attack chain involved exploiting the wsproxy bypass to access localhost services, interacting with CouchDB to read and write files as the couchdb user, staging malicious files in the temporary directory, obtaining the appliance product UUID, and exploiting the remove_hotfix path traversal flaw associated with CVE-2026-15410 to gain root level command execution. With root privileges, attackers were able to access stored and cached credentials, capture network traffic, and potentially intercept credentials processed by the affected VPN appliances. Volexity stated that while UTA0533 demonstrated advanced capabilities in compromising SonicWall SMA devices through chained zero day vulnerabilities, available evidence indicates the threat actor achieved limited success in moving laterally or gaining access to additional systems within the targeted environment.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.