SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware.

In early July 2026, the cybersecurity firm Volexity was involved in investigating an intrusion related to the SonicWall Secure Mobile Access VPN appliances.

The investigation discovered that a threat actor, identified as UTA0533, had chained multiple zero-day vulnerabilities to compromise these devices, deploy custom malware, capture network traffic, and attempt lateral movement within victim networks.

SonicWall 0-day Vulnerabilities Exploited

Volexity found evidence that exploitation began as early as June 22, 2026. SonicWall disclosed the vulnerabilities on July 14, 2026, affecting SMA 1000 series models (6210, 7210, and 8200v), and fixed them with hotfixes 12.4.3-03453 and 12.5.0-02835.

The attack chain exploited CVE-2026-15409, an SSRF flaw that let unauthenticated attackers abuse the /wsproxy endpoint to establish WebSocket tunnels to localhost services, and CVE-2026-15410, a command injection vulnerability used to gain code execution.

This exposure granted access to internal services, such as CouchDB on port 1050 and the SMA control service on port 8188. The attackers used these exposed internal services to upload files and gather information necessary to access privileged functions.

CVE-2026-15410 enabled path traversal in the execRemoveHotfix function, which allowed a file placed in /tmp to execute with root privileges. Log entries referencing “remove_hotfix” and paths like “../../../../../tmp/1234.sh” are strong indicators of exploitation.

On one compromised appliance, UTA0533 installed a setuid root execution tool named xzfind, internally referred to as ROOTRUN. The group also deployed a Python-based implant called KNUCKLEBALL, saved as deploy_new.py.

This malware injected Java payloads into a legitimate SonicWall process and achieved persistence by modifying a startup script. The injected payloads included Suo5, an HTTP proxy-forwarding tool, and ORANGETAIL, a custom Java webshell resembling Behinder.

The attackers altered the NGINX Unit configuration to redirect requests from /api/login and /api/logout to the hidden implants. The backdoors required an unusual and invalid browser user-agent string to function, helping them avoid casual detection.

Volexity also observed post-compromise activity, including the use of tcpdump to capture unencrypted LDAP traffic. The attackers appeared to be seeking usernames and passwords while attempting to pivot from the VPN appliances to internal systems.

Organizations are advised to immediately apply SonicWall’s fixes, review /var/log/aventail/ logs for suspicious /wsproxy activity, inspect /tmp and /var/tmp for unexpected files, and check /var/lib/unit/conf.json for unauthorized routes pointing to 127.0.0.1:8085. Volexity has also published YARA rules to detect ROOTRUN, KNUCKLEBALL, and related payloads.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment