ORANGETAIL is a custom Java memory-resident web shell used in intrusions against SonicWall SMA 1000 series secure remote access appliances. It is modeled after the Behinder framework and was observed in 2026 exploitation chains involving CVE-2026-15409 and CVE-2026-15410, where attackers obtained root-level access to vulnerable appliances and deployed multiple implants for persistence, covert access, and internal network pivoting. The activity has been attributed by investigators to the threat cluster UTA0533, and later reporting linked the broader exploitation wave to ransomware operations including INC Ransomware.
ORANGETAIL was deployed alongside other tooling including the KNUCKLEBALL Python loader, the Suo5 proxy, and the ROOTRUN privilege-enabling utility. KNUCKLEBALL injected ORANGETAIL into a legitimate SonicWall Java process using the Java Attach API, allowing the web shell to remain memory-resident and reducing on-disk visibility. The implant was exposed through modified web routing on the appliance, enabling covert access through attacker-controlled application paths while blending with legitimate web application behavior. Investigators also reported startup and web-server configuration changes used to preserve access across reboots and maintain routing to implanted components.
Functionally, ORANGETAIL acts as a covert server-side execution mechanism. It only responds to specially crafted requests carrying an expected spoofed browser identification string and otherwise can present benign-looking responses, supporting defense evasion. It executes Java payloads supplied by the operator and has been described as using encrypted request handling consistent with Behinder-style tradecraft. In the observed campaigns, compromised appliances were then used to support credential theft opportunities, interception of authentication material, traffic capture, and attempted lateral movement into internal enterprise environments. The malware targeted SonicWall SMA 1000 appliances running a Linux-based platform and formed part of a broader post-exploitation toolkit tailored for edge-device compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances - CVE-2026-15409 (Server-Side Request Forgery, CVSSv3.1 10.0) and CVE-2026-15410 (Code Injection / path traversal, CVSSv3.1 7.2) - which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. | Match against known malware from this campaign ... Malware File MD5 ORANGETAIL (webshell) agent_wp9.jar 5f3a55201c511c9ff9be4c16c41028a2
CVE-2026-15410 — Code Injection / Path Traversal Severity: High (CVSSv3.1 7.2). Vulnerability type: Path traversal in the remove_hotfix helper invoked by the appliance's control-service sysCtrl.execRemoveHotfix function, which normally requires administrator access to the Appliance Management Console (AMC). | Match against known malware from this campaign ... Malware File MD5 ORANGETAIL (webshell) agent_wp9.jar 5f3a55201c511c9ff9be4c16c41028a2
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Match against known malware from this campaign ... Malware File MD5 ORANGETAIL (webshell) agent_wp9.jar 5f3a55201c511c9ff9be4c16c41028a2
17 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
Host a persistent, appliance-specific webshell that survives casual inspection... Malware File... ORANGETAIL (webshell) agent_wp9.jar
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
Gating user-agent Mozilla/6.0 ... User-agent required to activate implanted components
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
Custom Behinder-like Java web shell used in the SonicWall SMA exploitation campaign.
A memory-resident Java web shell agent used on compromised SonicWall SMA appliances for covert remote access and command execution.
A memory-resident Java web shell agent used on compromised SonicWall SMA appliances for covert access and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.