Skip to content
← All Threat Actors
Nation-State critical China (PRC) — suspected

UTA0533

Suspected Chinese state-sponsored (Volexity — assessed based on targeting, custom implant capability, and infrastructure overlaps; not definitively attributed) · Espionage / credential harvesting / persistent network access

Reports 1
Active Since 2026
Last Reported 22 Jul 2026
Sectors Targeted government, defense, finance, enterprise

Tactics, Techniques & Procedures (TTPs)

  • Zero-day exploitation of SonicWall SMA 1000 (CVE-2026-15409 pre-auth file read + CVE-2026-15410 authenticated OS command injection)
  • Two-vulnerability chain providing unauthenticated RCE without breaking authentication mechanism
  • KNUCKLEBALL: passive credential-harvesting shared library hooking SMA 1000 authentication stack — no outbound C2 connections, accumulates credentials to hardware-keyed encrypted local store
  • ROOTRUN: persistent backdoor surviving firmware updates via non-standard configuration partition persistence and init hook
  • SSH-based tunneling on port 443 from compromised appliances to attacker-controlled servers
  • Token replay using session credentials extracted via CVE-2026-15409 — legitimate session appears in auth logs

Known Targets

Government agencies (North America and Europe)Defence contractorsLarge enterprise organisations with SonicWall SMA 1000 deployments

Analyst Notes

Disclosed by Volexity on July 17, 2026. UTA0533 exploited two zero-day vulnerabilities in SonicWall SMA 1000 series SSL-VPN appliances in a targeted espionage campaign against government and enterprise organisations. The custom implant set — KNUCKLEBALL for passive credential collection and ROOTRUN for persistent access — demonstrates significant development capability and operational security discipline. KNUCKLEBALL's passive design (no outbound network connections) makes it resistant to conventional C2 detection. ROOTRUN's firmware-update survival via non-standard partition persistence indicates hardware testing and appliance-specific development investment. Dwell time in confirmed cases ranged from six weeks to approximately four months before discovery. SonicWall released patches in firmware 12.4.3-02854 on July 14, 2026, three days before Volexity's disclosure.

Also Known As

UTA0533 (Volexity designation)