KNUCKLEBALL is a Python-based malware loader used in intrusions targeting SonicWall SMA 1000 series secure remote access appliances. It has been associated with the threat cluster UTA0533 and was observed in exploitation chains leveraging CVE-2026-15409 and CVE-2026-15410 to obtain root-level access on vulnerable appliances. After compromise, KNUCKLEBALL serves as the primary loader for additional in-memory implants rather than acting as a standalone payload.
Its core function is to inject embedded Java payloads into a legitimate SonicWall Java process using the Java Attach API. Observed payloads include Suo5, used for covert proxying and traffic forwarding, and ORANGETAIL, a custom memory-resident Java web shell modeled on Behinder-like tradecraft. This approach helps the operator blend malicious functionality into trusted appliance processes and reduces on-disk exposure of the final implants.
KNUCKLEBALL has also been used to establish persistence by modifying appliance startup behavior so the loader is re-executed after reboot. In observed incidents, it formed part of a broader post-compromise toolkit that enabled covert access, web-shell functionality, credential interception opportunities, and pivoting from the VPN appliance into internal environments. Activity linked to the same intrusion set included capture of unencrypted LDAP traffic and attempts at lateral movement, indicating that compromised appliances were used as high-value footholds for follow-on operations.
The malware targets Linux-based SonicWall SMA 1000 appliances and is notable for being tailored to the appliance environment, including direct interaction with SonicWall Java components. Its role in these intrusions is best characterized as a loader specialized for stealthy deployment of memory-resident post-exploitation implants on edge infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-15410 — Code Injection / Path Traversal Severity: High (CVSSv3.1 7.2). Vulnerability type: Path traversal in the remove_hotfix helper invoked by the appliance's control-service sysCtrl.execRemoveHotfix function, which normally requires administrator access to the Appliance Management Console (AMC). | Match against known malware from this campaign ... Malware File MD5 KNUCKLEBALL (dropper) deploy_new.py b6df166291f80ee89032d769c99714f3
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances - CVE-2026-15409 (Server-Side Request Forgery, CVSSv3.1 10.0) and CVE-2026-15410 (Code Injection / path traversal, CVSSv3.1 7.2) - which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. | Match against known malware from this campaign ... Malware File MD5 KNUCKLEBALL (dropper) deploy_new.py b6df166291f80ee89032d769c99714f3
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Match against known malware from this campaign ... Malware File MD5 KNUCKLEBALL (dropper) deploy_new.py b6df166291f80ee89032d769c99714f3
20 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
attackers used the appliance's embedded CouchDB service — which ships with hard-coded default credentials — to stage a script and trigger the path-traversal flaw. This allowed root command execution without any valid SMA administrator credentials.
Execution (T1059.004, Unix Shell): через AMC отправляется payload с code injection (CVE-2026-15410), выполняющий произвольные OS-команды на Linux-based ОС SMA1000.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
With root access, the operators deployed a durable backdoor, a covert forwarding tool and a memory-based web shell.
With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader)
Deploy persistence: The attacker modifies startup scripts and configuration files to keep access after restart.
Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.
The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy
The first embedded JAR file was the open-source HTTP proxy-forwarding tool Suo5.
Volexity later revealed that a threat actor tracked as UTA0533 began exploiting the vulnerabilities as early as June 22 (weeks before SonicWall publicly disclosed the flaws) to deploy custom malware known as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable VPN appliances.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed on vulnerable SonicWall SMA1000 VPN appliances following exploitation of CVE-2026-15409 and CVE-2026-15410.
A Python loader used to inject malicious Java agents onto compromised SonicWall SMA appliances.
A Python loader used to inject malicious Java agents onto compromised SonicWall SMA appliances.
A Python loader that decodes embedded JAR payloads, writes them to /tmp, injects them into the SonicWall Workplace JVM via the Java Attach API, clears traces, and establishes persistence by modifying init scripts and NGINX Unit configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.