bleeping-computer · Crawled Jul 20, 2026

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

3 IoCs
Read original article ↗

AI Summary

A previously unknown threat actor, tracked as UTA0533, exploited two zero-day vulnerabilities in SonicWall SMA1000 appliances to deploy custom malware. The attack chain began with a server-side request forgery (SSRF) vulnerability (CVE-2026-15409) to access internal services, followed by a command injection flaw (CVE-2026-15410) to execute commands as root. The attackers deployed a custom Python dropper named KNUCKLEBALL, which installed Java-based malware Sou5 and ORANGETAIL for persistent access and command execution.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Filename deploy_new.py Details →
Filename agent_wp8.jar Details →
Filename agent_wp9.jar Details →