SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Critical SonicWall Zero-Days Exploited for Weeks Before Patch Release

Cybersecurity firm Volexity has revealed that two recently patched vulnerabilities in SonicWall appliances were exploited by a threat actor known as UTA0533 for several weeks before patches became available. The flaws, identified as CVE-2026-15409 and CVE-2026-15410, allowed remote attackers to gain unauthorized access to SMA1000 secure remote access appliances.

According to Volexity, the exploitation of these zero-days began as early as June 22, with the threat actor deploying custom malware named KnuckleBall onto compromised devices. Once inside, the attackers injected two additional tools: OrangeTail, a tailored Java webshell, and Suo5, an open-source proxy. With root access, the attackers could access sensitive credentials, capture network traffic, and potentially intercept other sensitive information.

The fact that these vulnerabilities were exploited for weeks before patches were released highlights the importance of prompt vulnerability disclosure and patching. SonicWall’s public advisory on July 14 provided crucial information to customers about the affected appliances and available hotfix releases. However, it appears that not all users had taken necessary precautions by this point, leaving them vulnerable to attack.

Volexity’s investigation suggests that UTA0533 is a state-sponsored Advanced Persistent Threat (APT) group rather than a financially motivated cybercrime operation. This conclusion is based on the sophistication of the attacks and the resources likely required to carry out such operations. The motivation behind these attacks remains unclear, but it is possible that they were aimed at gathering sensitive information or disrupting critical infrastructure.

It’s worth noting that the Common Vulnerabilities and Exposures (CVE) catalog now lists 17 flaws affecting SonicWall products, highlighting the importance of regular security updates and patch management for users. While Volexity has shared indicators of compromise (IoCs) and technical details related to these attacks, further analysis is needed to fully understand the scope and impact of this incident.

In light of this incident, it’s essential for all SonicWall appliance users to prioritize patching and ensure that their systems are up-to-date with the latest security fixes. This includes not only applying hotfix releases but also regularly reviewing system logs and monitoring network activity for any signs of suspicious behavior. By taking proactive measures, organizations can significantly reduce their exposure to such attacks and maintain a robust cybersecurity posture.


Source: SecurityWeek — 2026-07-20