ROOTRUN is a Linux privilege-escalation utility used in intrusions against SonicWall SMA 1000 series secure remote access appliances. It has been observed in exploitation chains associated with threat actor UTA0533 and later reporting linked overlapping activity to INC Ransomware operations targeting internet-facing VPN gateways through CVE-2026-15409 and CVE-2026-15410.
ROOTRUN is a malicious setuid ELF binary designed to let an unprivileged user execute arbitrary commands with root privileges. On compromised appliances it functioned as a durable root-execution backdoor after initial exploitation had already provided elevated access, helping attackers preserve privileged command execution and maintain control of the device. Reporting consistently describes it as enabling arbitrary command execution as root rather than as a standalone initial-access mechanism.
In observed campaigns, ROOTRUN was deployed alongside other appliance-focused malware including KNUCKLEBALL, Suo5, and ORANGETAIL. KNUCKLEBALL acted as a loader that injected Java payloads into a legitimate SonicWall process, while Suo5 provided covert forwarding and ORANGETAIL supplied a memory-resident web shell. Together, these tools supported persistent access, covert remote operations, credential collection opportunities, traffic interception, and attempted pivoting into internal enterprise networks.
The broader post-compromise activity on affected appliances included persistence changes to startup and routing configuration, capture of unencrypted LDAP traffic, access to cached credentials and session material, and use of the VPN appliance as a foothold for lateral movement. ROOTRUN’s role within this toolkit was to provide reliable privileged execution on Linux-based appliance systems after compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances - CVE-2026-15409 (Server-Side Request Forgery, CVSSv3.1 10.0) and CVE-2026-15410 (Code Injection / path traversal, CVSSv3.1 7.2) - which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. | Match against known malware from this campaign ... Malware File MD5 ROOTRUN /usr/bin/xzfind 5cb00bbfe818ee3e85fb99ab1db1af7c
CVE-2026-15410 — Code Injection / Path Traversal Severity: High (CVSSv3.1 7.2). Vulnerability type: Path traversal in the remove_hotfix helper invoked by the appliance's control-service sysCtrl.execRemoveHotfix function, which normally requires administrator access to the Appliance Management Console (AMC). | Match against known malware from this campaign ... Malware File MD5 ROOTRUN /usr/bin/xzfind 5cb00bbfe818ee3e85fb99ab1db1af7c
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Match against known malware from this campaign ... Malware File MD5 ROOTRUN /usr/bin/xzfind 5cb00bbfe818ee3e85fb99ab1db1af7c
12 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
The attack chain allowed the threat actor to compromise vulnerable SonicWall SMA VPN appliances, access localhost-only services, execute commands, escalate privileges, deploy malware, modify configuration files, and gain root-level access.
The second can turn a low-privilege foothold into root control by causing a staged script to run with full system rights.
Persistence artefacts /etc/init.d/workplace /var/lib/unit/conf.json Modified files used for persistence and route hijacking
altered startup and routing settings helped implants survive restarts
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
A malicious setuid binary deployed after root compromise to provide privileged execution and persistence on compromised SonicWall SMA appliances.
A malicious setuid binary deployed after appliance compromise to provide root-level execution and persistence on affected SonicWall SMA appliances.
A malicious setuid ELF binary installed after root compromise that allows unprivileged users to execute arbitrary commands as root, providing durable local privilege escalation and persistent backdoor access on compromised SonicWall SMA appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.