UTA0533
Suspected Chinese state-sponsored (Volexity — assessed based on targeting, custom implant capability, and infrastructure overlaps; not definitively attributed) · Espionage / credential harvesting / persistent network access
Tactics, Techniques & Procedures (TTPs)
- Zero-day exploitation of SonicWall SMA 1000 (CVE-2026-15409 pre-auth file read + CVE-2026-15410 authenticated OS command injection)
- Two-vulnerability chain providing unauthenticated RCE without breaking authentication mechanism
- KNUCKLEBALL: passive credential-harvesting shared library hooking SMA 1000 authentication stack — no outbound C2 connections, accumulates credentials to hardware-keyed encrypted local store
- ROOTRUN: persistent backdoor surviving firmware updates via non-standard configuration partition persistence and init hook
- SSH-based tunneling on port 443 from compromised appliances to attacker-controlled servers
- Token replay using session credentials extracted via CVE-2026-15409 — legitimate session appears in auth logs
Known Targets
Analyst Notes
Disclosed by Volexity on July 17, 2026. UTA0533 exploited two zero-day vulnerabilities in SonicWall SMA 1000 series SSL-VPN appliances in a targeted espionage campaign against government and enterprise organisations. The custom implant set — KNUCKLEBALL for passive credential collection and ROOTRUN for persistent access — demonstrates significant development capability and operational security discipline. KNUCKLEBALL's passive design (no outbound network connections) makes it resistant to conventional C2 detection. ROOTRUN's firmware-update survival via non-standard partition persistence indicates hardware testing and appliance-specific development investment. Dwell time in confirmed cases ranged from six weeks to approximately four months before discovery. SonicWall released patches in firmware 12.4.3-02854 on July 14, 2026, three days before Volexity's disclosure.
Also Known As
MITRE ATT&CK Techniques