UTA0533 is an unattributed threat cluster tracked for pre-disclosure exploitation of SonicWall SMA 1000 secure remote-access appliances beginning in June 2026. The actor chained CVE-2026-15409 and CVE-2026-15410 to obtain unauthenticated access to localhost-restricted appliance services, execute commands, and gain root-level control. No public attribution links UTA0533 to a country, nation-state, or previously known threat group. Post-compromise activity included deployment of appliance-specific tooling: ROOTRUN, a setuid root-execution utility; KNUCKLEBALL, a loader that injected Java payloads into a legitimate SonicWall process; the Suo5 proxy; and ORANGETAIL, a custom Behinder-like Java web shell. UTA0533 modified appliance startup and web-routing configuration to establish persistence and conceal access to its implants. It also captured unencrypted LDAP traffic to collect credentials and attempted to authenticate to internal systems from compromised appliances. Investigations found the actor had achieved deep appliance compromise but indicated more limited success in lateral movement beyond the affected VPN infrastructure. Activity using the same vulnerability chain later overlapped tactically with ransomware-related operations, but UTA0533 itself remains unattributed and its motivation is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2026-15409 affects SonicWall SMA1000 and is cited as an active zero-day exploited by UTA0533 and INC Ransomware.
CVE-2026-15410 — Code Injection / Path Traversal Severity: High (CVSSv3.1 7.2). Vulnerability type: Path traversal in the remove_hotfix helper invoked by the appliance's control-service sysCtrl.execRemoveHotfix function, which normally requires administrator access to the Appliance Management Console (AMC).
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unattributed activity cluster cited as independently exploiting the SonicWall SMA1000 zero-day CVE-2026-15409 before ransomware activity.
An unattributed activity cluster identified as exploiting the SonicWall SMA1000 zero-day CVE-2026-15409, independently alongside a ransomware group.
Earlier exploitation activity targeting the same SonicWall SMA1000 vulnerability chain was linked to this cluster.
Exploited SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 as early as June 22 to deploy custom malware on vulnerable VPN appliances.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.