SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

A pair of previously unknown vulnerabilities in SonicWall’s SMA1000 secure remote access appliances has allowed hackers to compromise sensitive systems and deliver custom malware, with the issue remaining unpatched for weeks before a fix was released. Cybersecurity firm Volexity revealed that the flaws were exploited by a threat actor known as UTA0533, which used the vulnerabilities to deploy a sophisticated attack chain that ultimately gave them root access on targeted systems.

The exploits, identified as CVE-2026-15409 and CVE-2026-15410, allowed remote, unauthenticated attackers to breach the appliances without needing any login credentials. SonicWall released a public advisory on July 14, informing customers of the issue and providing hotfix releases to address the vulnerabilities. However, it appears that UTA0533 was exploiting these flaws as early as June 22, according to Volexity’s analysis.

Once inside the system, the attackers deployed custom malware called KnuckleBall, which injected two other tools into legitimate processes: a tailored Java webshell named OrangeTail and an open-source proxy named Suo5. With root access, the hackers could potentially capture network traffic, intercept credentials processed by the appliances, or even access stored or cached credentials.

The motivations behind UTA0533’s actions are unclear at this point, but Volexity believes that the attack is more consistent with state-sponsored Advanced Persistent Threat (APT) activity rather than a profit-driven cybercrime operation. While the attackers demonstrated significant capability in compromising the SonicWall appliances, available evidence suggests they were less successful in moving laterally or gaining access to other systems.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added the two vulnerabilities to its Known Exploit Vulnerabilities (KEV) catalog, which currently includes 17 flaws affecting SonicWall products. This highlights the ongoing threat posed by unpatched vulnerabilities, particularly in critical infrastructure devices like the SMA1000 appliances.

For users of SonicWall’s SMA1000 appliances, it is essential to ensure that the latest hotfix releases are applied as soon as possible. Additionally, organizations should review their security protocols and consider implementing additional measures to prevent similar attacks in the future. This includes regularly monitoring system logs for suspicious activity and maintaining up-to-date software patches.

In conclusion, the exploitation of these vulnerabilities serves as a reminder of the importance of timely patching and the need for continued vigilance against emerging threats. As the cybersecurity landscape continues to evolve, it is crucial that organizations prioritize proactive security measures to stay ahead of potential attacks.


Source: SecurityWeek — 2026-07-20