Atrás

From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain

Cyber Threat Intelligence

SonicWall SMA, CVE-2026-15409, CVE-2026-15410, INC Ransomware, VPN Security, Dark Web

 From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
 From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain

Introduction

Virtual private network (VPN) appliances occupy one of the most sensitive positions in modern enterprise architecture: the boundary between the untrusted public internet and the internal corporate network. Unlike general-purpose web servers, VPN concentrators are intentionally exposed to inbound connections, designed to authenticate remote users, and granted privileged access to directory services, file shares, intranet applications, and management interfaces. They terminate encrypted tunnels, process credentials, and maintain session state at the network edge. A critical vulnerability in a VPN appliance is therefore not a peripheral remote-access issue—it is a direct network-compromise issue with cascading consequences for every downstream system the appliance was built to protect.

On July 14, 2026, SonicWall published advisory SNWLID-2026-0008 for two critical vulnerabilities affecting the Secure Mobile Access (SMA) 1000 series. Patches were released the same week. The disclosure was preceded by active, pre-disclosure exploitation observed by Volexity beginning on June 22, 2026. The threat actor, tracked as UTA0533, chained both vulnerabilities to obtain root-level access to targeted appliances. Subsequent analysis by Rapid7 identified significant TTP overlap, and INC Ransomware has since emerged as the dominant actor actively weaponizing the full chain.

CISA added both CVEs to the Known Exploited Vulnerabilities (KEV) catalog with a remediation due date of July 17, 2026. As of August 1, 2026 - Resecurity may confirm that many of the devices still remain unpatched or compromised as a result of the previous wave of exploitation, which could be reused in further network intrusions. Based on our assessment, MTTD and MTTR in cases involving VPN concentrators may vary, leading to an extensive Window of Exposure (WoE). Since many enterprise networks could be managed by third parties, this may introduce additional delays in incident containment.

The two chained zero-days were:

  • CVE-2026-15409 — CVSS 10.0. A pre-authentication /wsproxy bypass allowing an unauthenticated external attacker to open a WebSocket tunnel to services intended to be accessible only from localhost.
  • CVE-2026-15410 — CVSS 7.2. A path-traversal flaw in the remove_hotfix workflow of ctrl-service, abused to escalate from a low-privilege service account to root.

When combined, these flaws transform a single unauthenticated HTTP request into full root control of a VPN gateway. The attacker can then intercept credentials, capture network traffic, deploy persistent malware, and pivot into internal infrastructure.

This report provides a consolidated technical analysis of the vulnerabilities, the source-code-level root causes, the precise mechanics of the attack chain, the malware and indicators of compromise observed in the wild, attacker infrastructure, independent research, and actionable defensive recommendations for incident response and long-term hardening.

Executive Summary

On July 14, 2026, SonicWall published advisory SNWLID-2026-0008 and released critical patches for the SMA 1000 series line of SSL-VPN appliances. The actively exploited primitives are CVE-2026-15409 and CVE-2026-15410, which were weaponized together by threat actor UTA0533 beginning at least June 22, 2026—before public disclosure. Volexity and Rapid7 have since linked the exploitation cluster to INC Ransomware, which has become the dominant threat actor actively weaponizing the vulnerability chain.

An unauthenticated attacker can chain these weaknesses to:

  1. Send a crafted request to the /wsproxy endpoint with spoofed client identifiers.
  2. Open a WebSocket tunnel to localhost-only services on the appliance.
  3. Interact with CouchDB and the Erlang-based ctrl-service without network segmentation.
  4. Read sensitive appliance files and stage an exploit payload on disk.
  5. Trigger the remove_hotfix path traversal to escalate privileges to root.
  6. Deploy persistent malware including ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL.

Organizations running unpatched, internet-facing SMA 1000 appliances should treat this as an active, high-impact incident requiring emergency response. Patching must be paired with compromise assessment, because a patched appliance that still contains attacker-planted malware remains compromised.

Why It Matters

VPN appliances are high-value targets because they aggregate identity, credentials, and network access. In a typical enterprise deployment, the SMA appliance is integrated with Active Directory or LDAP, terminates TLS sessions for remote employees and contractors, and stores certificates, session tokens, user databases, and authentication policies. A successful compromise turns the VPN gateway into a persistent surveillance and pivot point.

The business impact extends far beyond the appliance itself:

  • Credential interception — the appliance processes usernames, passwords, session cookies, and MFA state.
  • Traffic capture — root access enables packet capture of LDAP, RADIUS, and internal application traffic.
  • Lateral movement — the device sits at the edge and has routes into internal subnets, directory services, and management networks.
  • Durable persistence — setuid binaries, modified init scripts, and NGINX Unit config changes survive reboots.
  • Ransomware staging — INC Ransomware has been observed leveraging this chain as an entry point into enterprise networks.

Because the attack requires zero preconditions—no credentials, no authenticated session, no user interaction, and no prerequisite misconfiguration—every internet-facing, unpatched SMA 1000 appliance is a potential target. The presence of a CVSS-10.0 pre-auth bypass chained with a privilege-escalation primitive makes this one of the most severe VPN-appliance attacks of 2026.

Threat Actor Profile

Volexity tracks the pre-disclosure exploitation cluster as UTA0533. Rapid7’s later incident-response work identified a significant overlap in tactics, techniques, and procedures (TTPs) with its own investigations, leading both firms to conclude that a single actor or a closely coordinated group was responsible for the zero-day exploitation. More recently, INC Ransomware has emerged as the dominant threat actor weaponizing the full chain in the wild.

The observed TTPs align with:

  • Ransomware affiliates and initial-access brokers seeking privileged footholds for encryption and extortion.
  • Nation-state and espionage actors targeting government, defense, technology, and critical-infrastructure VPN concentrators.
  • High-skill opportunistic attackers capable of reverse-engineering appliance firmware, chaining zero-days, and developing custom Java implants.

Key behavioral indicators include:

  • Pre-disclosure exploitation beginning June 22, 2026.
  • Use of the User-Agent string “SMA Connect Agent” and URI parameter bmID=-3389 against /wsproxy.
  • Deployment of multi-stage malware: ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL.
  • Modification of /etc/init.d/workplace and /var/lib/unit/conf.json for persistence.
  • Use of tcpdump to capture unencrypted LDAP traffic and harvest domain credentials.

Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS). Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest.

 

 

The new victims listed on INC Ransomware's DLS between July 17, 2026 and August 1, 2026 include private sector and government organizations from Australia, the US, UAE, Colombia, Switzerland, and other countries. Resecurity has assisted several victims with DFIR and vulnerability assessments to contain the root cause of the compromise, but also learned about the following new developments: many of the new victims received emails, as well as phone calls from unknown organizations claiming to assist with ransomware issues.

For example, the domain name associated with one of these emails (used by threat actors to contact the victim organization) was registered shortly after the actual incident and the exploitation activity, which Resecurity believes began in June 2026—prior to the release of the official advisory and the availability of the patch. The domain name was registered through a Chinese domain registrar that accepts cryptocurrency payments.

Domain Name: HELPRANS[.]COM
Registry Domain ID: 3106477703_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.ordertld.com
Registrar URL: http://www.ordertld.com
Updated Date: 2026-06-02T11:54:59Z
Creation Date: 2026-06-02T10:48:13Z
Registry Expiry Date: 2027-06-02T10:48:13Z
Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED
Registrar IANA ID: 3254
Registrar Abuse Contact Email: abuse@ordertld.com
Registrar Abuse Contact Phone: +852.30501810
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Name Server: DENVER.NS.CLOUDFLARE.COM
Name Server: TESSA.NS.CLOUDFLARE.COM

The victims were also contacted by an individual who introduced himself as "Andrew" using the phone number +1 (304) 384-0401. He claimed to be calling "from a group of hackers" and stated that the victim's network had been compromised. At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as "pressure tactics." Resecurity recommends immediately contacting law enforcement if your organization faces such extortion demands.

Affected Products and Firmware Versions

Vendor: SonicWall
Advisory: SNWLID-2026-0008, published July 14, 2026

Affected Models

  • SMA 6210
  • SMA 7210
  • SMA 8200v
  • CMS (all hypervisors)

Affected Firmware Versions

12.4.3 branch:

  • 12.4.3-03245
  • 12.4.3-03387
  • 12.4.3-03434

12.5.0 branch:

  • 12.5.0-02283
  • 12.5.0-02624
  • 12.5.0-02800

Fixed Firmware Versions

  • 12.4.3-03453 and later
  • 12.5.0-02835 and later

Important: These vulnerabilities do not affect SonicWall firewall SSL VPN or the SMA 100 Series. There are no workarounds—upgrade to a fixed firmware version is the only remediation. Both CVEs were added to the CISA KEV catalog with a remediation due date of July 17, 2026.

SonicWall SMA Technology Overview

SMA 1000 Appliance Architecture

The SonicWall Secure Mobile Access (SMA) 1000 Series is an enterprise SSL VPN platform that provides secure remote access to internal corporate resources. Positioned at the network perimeter, the appliance authenticates remote users, terminates VPN sessions, and brokers access to internal applications, directory services, file shares, and management interfaces.

Unlike a traditional web server, the SMA appliance operates as a multi-tier application composed of several interconnected services. Internet-facing components communicate with multiple backend services responsible for authentication, configuration management, session handling, and system administration. These services are intentionally separated by network boundaries and privilege levels to reduce the impact of a compromise.

A typical SMA 1000 deployment includes the following components:

  • NGINX / NGINX Unit (Front-End) — Terminates inbound HTTPS connections, processes WebSocket requests, and routes client traffic to backend services.
  • workplace Web Application — Provides the primary user portal and administrative interface.
  • /wsproxy Endpoint — A WebSocket proxy used by legitimate SMA Connect clients to communicate with selected backend services.
  • ctrl-service — A privileged internal management service for administrative workflows, diagnostics, hotfix installation/removal, packet capture, and other system-level operations.
  • CouchDB — A local NoSQL database storing configuration, session information, and application data.
  • Erlang Distribution Services — Internal Erlang-based services, including the control service listening on localhost:1050.
  • Linux Operating System — The underlying OS. Services execute under dedicated accounts such as couchdb, while privileged operations are restricted to root.

During normal operation, only the NGINX front-end is intended to accept external connections. Backend components—including CouchDB, ctrl-service, and Erlang services—are bound exclusively to the localhost interface. This design creates a layered security architecture in which internal services trust requests originating only from the local host.

The security model assumes that the front-end performs all necessary authentication, authorization, and request validation before forwarding traffic internally. Consequently, backend services expose administrative functionality without expecting direct interaction from untrusted users.

The exploitation of CVE-2026-15409 fundamentally breaks this assumption. By abusing the /wsproxy endpoint, an unauthenticated attacker can establish a WebSocket tunnel that bypasses intended routing restrictions and communicate directly with localhost-only services. Once this trust boundary is removed, previously isolated components become externally reachable, enabling the remainder of the exploit chain that ultimately results in full root compromise.

Appliance Trust Boundaries

The SMA 1000 security architecture relies on network isolation and service segmentation. Internet-facing requests are expected to terminate at the NGINX front-end, which authenticates users and selectively forwards approved traffic to backend applications. Administrative services such as CouchDB and ctrl-service are intentionally restricted to the localhost interface and are never designed to communicate directly with external clients.

The /wsproxy vulnerability invalidates this architectural assumption. Rather than enforcing strict backend routing, the vulnerable implementation allows specially crafted WebSocket requests to be proxied to arbitrary localhost services. As a result, an unauthenticated external attacker can cross the trust boundary separating the public network from internal management components.

Once this boundary is breached, the attacker gains direct access to backend services that implicitly trust localhost traffic. This access enables interaction with CouchDB, execution of privileged management functions through ctrl-service, and ultimately the privilege-escalation workflow exploited by CVE-2026-15410.

Key trust-boundary takeaways:

  • Only the NGINX/NGINX Unit front-end should be reachable from the public Internet.
  • CouchDB, ctrl-service, and Erlang services depend on localhost binding as their primary network isolation mechanism.
  • /wsproxy unintentionally becomes a bridge between external clients and privileged backend services, collapsing the intended trust boundary.
  • Once the WebSocket tunnel is established, backend services process requests as though they originated locally.
  • On physical SMA appliances, the UUID-derived ctrl-service password introduces an additional weakness because /sys/class/dmi/id/product_uuid is world-readable, allowing low-privileged users to derive administrative credentials. This weakness was not required in the observed exploit chain but further weakens the overall trust model.

The Source-Code Root Cause

SonicWall appliance firmware is proprietary, so the exact source is not public. However, the vulnerability behavior can be reconstructed from published technical analysis and incident-response artifacts.

CVE-2026-15409 — /wsproxy SSRF

The WorkPlace application exposes /wsproxy as a WebSocket-to-TCP proxy. Conceptually, the handler looks like this:

// Conceptual reconstruction of the vulnerable handler
@ServerEndpoint("/wsproxy")
public class WsProxyServlet {
    @OnOpen
    public void onOpen(Session session) {
        // All three values come from the attacker-controlled upgrade request
        String host = session.getRequestParameterMap().get("host").get(0);
        String port = session.getRequestParameterMap().get("port").get(0);
        String serviceType = session.getRequestParameterMap().get("serviceType").get(0);

        // BUG: no authentication, no origin check, no backend whitelist
        Socket backend = new Socket(host, Integer.parseInt(port));

        // Bidirectionally relay WebSocket <-> TCP
        relay(session, backend);
    }
}

 

The only gating is client-supplied metadata:

  • User-Agent: SMA Connect Agent
  • bmID parameter beginning with -3389
  • serviceType such as SSH or TELNET

None of these prove legitimacy—they are trivially spoofed. The appliance opens the outbound TCP connection itself, so the request originates from the loopback interface. By setting host=0.0.0.0, 127.0.0.1, or localhost, the attacker reaches services that rely on localhost as their access control.

CVE-2026-15410 — remove_hotfix Path Traversal

The ctrl-service daemon exposes a hotfix-removal workflow that trusts the caller-supplied hotfix path. Conceptually:

# Conceptual reconstruction of the vulnerable workflow
def remove_hotfix(hotfix_path):
    working_dir = "/var/lib/aventail/avp/rollback/"
    target = working_dir + hotfix_path          # BUG: no normalization, no chroot
    os.chmod(target, 0o755)
    subprocess.run(["/bin/bash", target, "--unattended"])

 

Because the path is concatenated rather than normalized, traversal sequences such as ../../../../../tmp/1234.sh resolve to an attacker-controlled file outside the hotfix directory. The workflow then chmods and executes that file as root.

The Attack Chain: From bmID=-3389 to root

SonicWall SMA VPN Appliance Exploit Chain

Step 1 — Target SonicWall SMA VPN 1000 Appliances

The attacker identifies internet-facing SonicWall SMA 1000 series VPN appliances. These devices are attractive because they are exposed to inbound HTTPS traffic, process credentials for remote users, and often have privileged access to internal directory services and management networks. No reconnaissance beyond identifying the appliance model and firmware version is required.

Step 2 — Send an Unauthenticated /wsproxy Request

The attacker sends a single WebSocket upgrade request to /wsproxy with spoofed client identifiers:

  • User-Agent: SMA Connect Agent
  • URI parameter bmID = -3389
  • serviceType=SSH
  • host=0.0.0.0 or 127.0.0.1
  • port=1050 (Erlang/CouchDB) or port=8188 (ctrl-service)

These values are trusted by the front-end as markers of legitimate internal client traffic. Because the request is unauthenticated, the attacker does not need valid VPN credentials, a session cookie, or MFA state.

GET /wsproxy?bmID=-3389c1b25ccd&serviceType=SSH&host=0.0.0.0&port=1050 HTTP/1.1
Host: <target appliance>
User-Agent: SMA Connect Agent
Upgrade: websocket
Connection: Upgrade

 

Rapid7’s published PoC weaponizes this against the Erlang process on localhost:1050. The Erlang cookie is effectively hardcoded across devices, so authentication is not required once the tunnel is established:

python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&serviceType=SSH&host=0.0.0.0&port=1050' \
  --ws-user-agent 'SMA Connect Agent' \
  --ws-insecure-tls \
  --cookie 10ecad5b446e86864832904cd439b6b70262 \
  --exec 'whoami && id && pwd && hostname'

 

This yields execution as user couchdb (uid=1010) in /opt/couchdb.

Step 3 — Establish a WebSocket Tunnel to Localhost-Only Services

After the front-end accepts the request, a WebSocket tunnel is created. The attacker directs the tunnel to internal services bound to localhost, bypassing the network-layer isolation that normally protects them. Services reachable through this tunnel include CouchDB / Erlang distribution on localhost:1050 and ctrl-service on localhost:8188. This step collapses the trust boundary between externally exposed handlers and internal appliance services.

Step 4 — Make Calls to CouchDB to Read/Write Files as the couchdb User

Using the tunnel, the attacker communicates with CouchDB. Because CouchDB runs as the couchdb user and exposes file read/write primitives through its APIs, the attacker can perform filesystem operations in the context of that account. This is not root, but it provides a stable foothold on the appliance and access to files that are world-readable or CouchDB-readable.

Step 5 — Stage a File in /tmp as the couchdb User

The attacker writes a staged script to /tmp through CouchDB. In the observed chain, this staged file (/tmp/1234.sh) reads /sys/class/dmi/id/product_uuid when executed. On physical appliances, the UUID is a world-readable hardware identifier that is also used to derive the ctrl-service administrative password. Even when the UUID-derived password path is not used, staging a file in /tmp provides the payload needed for the next execution step.

Step 6 — Invoke sysCtrl.execTcpdumpStart or Execute Directly Through CouchDB

The attacker obtains command execution on the appliance by invoking the sysCtrl.execTcpdumpStart function or by executing the staged file directly through CouchDB. This yields code execution in the context of a low-privilege service account. While not yet root, this foothold is sufficient to interact with ctrl-service and to stage the privilege-escalation exploit.

Step 7 — Invoke sysCtrl.execRemoveHotfix with Path Traversal

The attacker triggers CVE-2026-15410 by calling sysCtrl.execRemoveHotfix with a path-traversal payload. The vulnerable endpoint is POST /rollbackConfirm.action. The attacker supplies a hotfix parameter containing traversal sequences:

POST /rollbackConfirm.action HTTP/1.1
Host: <target SMA appliance>
Content-Type: application/x-www-form-urlencoded

csrfToken=<valid token>&command=rollback&rollbackUpgradeTime=&hotfix=../../../../../tmp/1234.sh&rollbackHotfixTime=

 

Behind the scenes, ctrl-service calls /usr/local/bin/remove_hotfix from its working directory /var/lib/aventail/avp/rollback/. The unsanitized path resolves to the attacker’s staged script:

chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
/bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
shutdown -r now

 

Because remove_hotfix runs as root, the attacker’s script executes with full privileges, typically followed by an immediate reboot.

Investigators found the privilege-escalation exploit encoded as /tmp/hypdate.b64 on compromised appliances, owned by the unprivileged couchdb account—clear evidence the actor could write and execute through that service context.

Step 8 — Deploy KNUCKLEBALL Malware and Inject Suo5 & ORANGETAIL into Memory

With root access, the attacker deploys the full malware toolkit:

  • KNUCKLEBALL (/usr/lib/python3.11/site-packages/deploy_new.py) — a Python injector that loads embedded JAR archives into a legitimate SonicWall process.
  • Suo5 — an open-source HTTP proxy embedded by KNUCKLEBALL for covert tunneling.
  • ORANGETAIL — a custom Java web shell similar to Behinder, providing encrypted command-and-control over HTTPS.

The malware is injected into memory rather than written to disk as standalone binaries, reducing the forensic footprint and complicating detection. Persistence is maintained through modifications to /etc/init.d/workplace and /var/lib/unit/conf.json, ensuring the implants survive reboots and may persist even after a superficial firmware upgrade.

UUID-Derived Control Service Password (Not CVE-Assigned)

A related weakness affects physical SMA appliances: the ctrl-service Basic-auth password is derived from the appliance hardware identifier in /sys/class/dmi/id/product_uuid. Because this file is world-readable on physical devices, any local user or service account that can read it can predict the control-service password.

The authentication bypass works as follows:

  1. The appliance generates the ctrl-service Basic Authentication password using the hardware UUID.
  2. The UUID is stored in /sys/class/dmi/id/product_uuid, which is world-readable on physical SMA appliances.
  3. After obtaining a low-privileged foothold (for example, through CouchDB or another local service), the attacker reads the UUID.
  4. Using the known password derivation algorithm, the attacker computes the ctrl-service administrative password.
  5. The attacker authenticates to ctrl-service with full administrative privileges, bypassing the need to exploit the remove_hotfix workflow.

Successful exploitation may allow an attacker to authenticate directly to ctrl-service, invoke privileged administrative functions, execute diagnostic or management operations, simplify post-exploitation activities, and accelerate privilege escalation after obtaining an initial foothold.

Exploitation prerequisites:

  • Physical SMA 1000 appliance (virtual appliances are not affected in the same way).
  • Ability to read /sys/class/dmi/id/product_uuid, which is world-readable on affected physical devices.

Volexity noted this bypass was not used in the observed UTA0533 incident, but it remains a noteworthy exposure for physical hardware deployments.

Malware Analysis

Following successful exploitation of the SonicWall SMA appliance, UTA0533 deployed a multi-stage malware toolkit designed to establish persistence, maintain covert command-and-control (C2), harvest credentials, and facilitate long-term access. Rather than relying on a single payload, the attackers deployed several specialized components that work together to achieve different post-exploitation objectives.

The primary malware family consists of ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL, supported by several helper scripts and persistence mechanisms.

Malware deployment chain

ROOTRUN

Location: /usr/bin/xzfind

ROOTRUN is a malicious setuid ELF binary (internally named rootrun) installed after root compromise. The binary provides a durable local privilege-escalation mechanism by allowing any unprivileged user to execute arbitrary commands with root privileges.

Unlike transient exploit payloads, ROOTRUN functions as a persistent backdoor that remains available even if the web shells are removed.

Characteristics
Property Value
Type setuid ELF binary
Size 13.1 KB (13,464 bytes)
Internal Name rootrun
MD5 5cb00bbfe818ee3e85fb99ab1db1af7c
SHA1 04d4a9fbb32e967200eb98be014ca914a03bfa6b
SHA256 81a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2
Purpose Persistent root execution

 

Execution Flow

ROOTRUN elevates via setuid() to root, then runs an attacker-supplied command through bash. Its internal usage string is:

Usage: rootrun rootrun <command>

Because the binary is setuid root, any unprivileged user who can execute /usr/bin/xzfind can run commands as root. This provides a recovery backdoor if the memory-resident web shells are removed or if the appliance is rebooted.

ROOTRUN was first observed on Appliance 1, written to disk on 2026-06-22.

ROOTRUN execution flow

KNUCKLEBALL

Location: /usr/lib/python3.11/site-packages/deploy_new.py

KNUCKLEBALL is the primary malware loader responsible for deploying the remaining implants. Instead of dropping standalone malware, it injects malicious Java agents directly into the legitimate SonicWall JVM using the Java Attach API. This greatly reduces forensic artifacts while allowing the implants to execute inside trusted application processes.

Characteristics
Property Value
Type Python Loader
Size 79.6 KB (81,476 bytes)
Target workplace.startup.CommandStartup
MD5 b6df166291f80ee89032d769c99714f3
SHA1 b4ee1f50fbb49f0ff5fde3d026343bc23ee08d51
SHA256 8c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3

 

Key Capabilities
  • Decodes two base64-encoded embedded JAR archives.
  • Writes temporary agents into /tmp:
    • /tmp/agent_wp8.jar (Suo5)
    • /tmp/agent_wp9.jar (ORANGETAIL)
  • Locates the target JVM process by enumerating /proc/<PID>/cmdline.
  • Uses the Java Attach API through /tmp/.attach_pid<PID> and /tmp/.java_pid<PID> to load the JARs as instrumentation agents.
  • Effective agent command: load instrument false <path>.
  • Clears /tmp/agent_wp8.log and /tmp/agent_wp9.log, then symlinks them to /dev/null to erase forensic traces.
  • Appends python3 /usr/lib/python3.11/site-packages/deploy_new.py to /etc/init.d/workplace for startup persistence.
  • Rewrites /var/lib/unit/conf.json through the NGINX Unit Unix socket to add external routes:
    • /__api__/login → /workplace/error.jsp at http://127.0.0.1:8085
    • /__api__/logout → /workplace/dialogs/errorDialog.jsp at http://127.0.0.1:8085
Java Injection Process

KNUCKLEBALL performs the following injection sequence:

  1. Decode the embedded JAR payloads from base64 blobs inside the Python script.
  2. Write the decoded JARs to /tmp/agent_wp8.jar and /tmp/agent_wp9.jar.
  3. Enumerate running processes to find the workplace.startup.CommandStartup JVM.
  4. Create the Java Attach API handshake files (/tmp/.attach_pid<PID> and /tmp/.java_pid<PID>).
  5. Send the load instrument false /tmp/agent_wpX.jar command to the JVM.
  6. The JVM loads the agent into the target servlet class, transforming it into a live web shell / proxy.
  7. Clean agent logs and symlink them to /dev/null.
  8. Modify /etc/init.d/workplace so the loader re-runs at boot.
  9. Rewrite /var/lib/unit/conf.json to expose the implanted endpoints under innocuous API paths.

Java injection process

Suo5

Suo5 is a modified version of the open-source HTTP forwarding proxy designed to provide covert tunneling through the compromised appliance. Instead of running as a standalone application, Suo5 is injected directly into the Workplace JVM as a Java instrumentation agent.

Characteristics
Property Value
File /tmp/agent_wp8.jar
Size 33.7 KB (34,520 bytes)
MD5 54d21399b8b52b48a0fef68450593e45
SHA1 c2b0ae0a1f42a139abe4dd612676066ec1426394
SHA256 1e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edee
Injection Target com/aventail/jsp/workplace/error_jsp
External Route /__api__/login → /workplace/error.jsp

 

Capabilities
  • HTTP tunnel
  • Internal pivoting
  • Reverse proxy
  • Covert C2
  • Traffic forwarding

ORANGETAIL

ORANGETAIL is a custom Java memory-resident web shell modeled after Behinder 3.x. Rather than exposing a conventional JSP web shell, it injects itself into an existing servlet and communicates using encrypted requests.

Characteristics
Property Value
File /tmp/agent_wp9.jar
Size 21.3 KB (21,800 bytes)
MD5 5f3a55201c511c9ff9be4c16c41028a2
SHA1 5e5b716f2385c818ec61198be1a2a07a4560eac5
SHA256 ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081
Injection Target com/aventail/jsp/workplace/dialogs/errorDialog_jsp
External Route /__api__/logout → /workplace/dialogs/errorDialog.jsp
Request Parameter find (POST)
Encryption AES-128-ECB, base64-encoded, hardcoded key
Sessioning Hardcoded session key bound after first class load

 

Capabilities
  • Remote command execution
  • File upload/download
  • AES-encrypted communications
  • Session management
  • Memory-resident execution

Access Gating

Both implants intentionally ignore ordinary requests. They only activate when the request contains the following spoofed User-Agent:

Mozilla/6.0 (Windows NT 11.0; Win64; x64) AppleWebKit/1537.136 (KHTML, like Gecko) Chrome/149.0.0.1 Safari/1537.136

The deliberately implausible version numbers (Windows NT 11.0 and Chrome 149) provide defenders with a strong detection opportunity.

ORANGETAIL vs Behinder

Feature Behinder 3.x ORANGETAIL
Encryption AES AES-128-ECB
Base64 Decoder Standard Java classes Custom hand-rolled decoder
Loader Direct javax.crypto.Cipher import Fully reflective via Class.forName → getMethod → invoke
Session Password-derived Hardcoded session key
Request Parameter POST Body find
Response Raw AES bytes JSON wrapper: {"message":"ok","content":"<b64-aes>","statuscode":"200"}
Obfuscation Minimal Character-by-character via String.valueOf()
Default Behavior Always responds Returns 404 unless gating user-agent is present

 

Additional Post-Exploitation Artifacts

Artifact Path Purpose
Staged Script /tmp/1234.sh Reads hardware UUID, owned by couchdb
Privilege Escalation /tmp/hypdate.b64 Encoded CVE-2026-15410 payload
Suo5 Agent /tmp/agent_wp8.jar HTTP proxy agent
ORANGETAIL Agent /tmp/agent_wp9.jar Java web shell agent
LDAP Sniffer /var/tmp/lib.sh Launches tcpdump on TCP/389
Marker /var/tmp/txt Zero-byte root-owned post-exploitation artifact
Persistence /etc/init.d/workplace Relaunches KNUCKLEBALL on boot
Route Hijacking /var/lib/unit/conf.json Redirects /__api__/login and /__api__/logout to implants

 

Credential Harvesting

On a second compromised appliance, the attackers deployed /var/tmp/lib.sh to execute tcpdump against unencrypted LDAP traffic (TCP/389). This enabled passive interception of usernames and passwords transmitted between the SMA appliance and backend directory services.

The observed activity demonstrates that, even after achieving root access, the attackers continued to prioritize credential collection to facilitate lateral movement throughout the enterprise. Organizations using unencrypted LDAP should treat this as a reminder to migrate authentication traffic to encrypted protocols such as LDAPS or StartTLS.

Attacker Infrastructure and Network IOCs

In addition to host-based IOCs, UTA0533 activity generated several network-level indicators. These are useful for firewall blocking, SIEM correlation, and attribution.

Observed Source IPs

The following non-VPN source IPs were observed interacting with compromised appliances:

  • 42.200.172.14
  • 81.19.140.217
  • 89.117.20.1
  • 108.205.8.173
  • 147.45.51.19
  • 150.241.210.53
  • 202.8.105.201
  • 217.77.15.99

Rapid7-Observed ASN 206092 Infrastructure

Rapid7 identified attacker infrastructure associated with ASN 206092 (F.N.S Holdings Limited):

  • 45.131.194.0/24
  • 45.146.54.0/24
  • 63.135.161.0/24
  • 173.239.211.0/24
  • Individual IPs: 193.37.32.179, 193.37.32.214, 216.73.163.151, 216.73.163.158

Leaked Attacker Hostnames

Hostnames unintentionally leaked during observed lateral-movement activity:

  • DESKTOP-5P0TSCP
  • DESKTOP-IC3C80F
  • DESKTOP-KRLUI3J
  • KALI
  • localhost

Key Network Signatures

  • WebSocket upgrade to /wsproxy?bmID=-3389... returning HTTP 101.
  • /wsproxy requests with host=0.0.0.0, 127.0.0.1, ::ffff:127.0.0.1, or localhost and port=1050 / port=8188.
  • POST /__api__/login and POST /__api__/logout returning HTTP 200 with the gating user-agent.
  • Outbound connections or internal proxying patterns consistent with Suo5 tunneling.

Vulnerability Analysis

CVE-2026-15409 — Pre-Authentication /wsproxy Bypass (CVSS 10.0)

Root cause: The /wsproxy endpoint makes a routing decision based on client-supplied identifiers that are trivial to spoof. Specifically, a User-Agent containing “SMA Connect Agent” and a URI parameter beginning with bmID=-3389 are treated as proof that the request originates from a legitimate internal client. The endpoint does not authenticate the client or validate that the requested backend service is appropriate for an external origin.

The exploitation process consists of the following stages:

  1. The attacker sends an unauthenticated HTTP request to the /wsproxy endpoint requesting a WebSocket upgrade.
  2. The request contains the spoofed values:
    1. User-Agent: SMA Connect Agent
    2. bmID=-3389
  1. The NGINX front-end incorrectly classifies the request as originating from a legitimate SMA Connect client.
  2. The appliance establishes a WebSocket tunnel without requiring VPN authentication, session cookies, or multi-factor authentication.
  3. The attacker selects an internal destination, such as CouchDB or ctrl-service, causing the appliance to proxy traffic directly to localhost-only services.
  4. The attacker can now communicate directly with privileged backend services that normally trust only local requests.

CVE-2026-15409 attack flow

Successful exploitation allows an unauthenticated attacker to:

  • Bypass authentication entirely.
  • Establish arbitrary WebSocket tunnels into localhost-only services.
  • Access CouchDB, ctrl-service, and Erlang management services.
  • Break the intended trust boundary between the Internet and internal appliance components.
  • Obtain the initial foothold required to chain CVE-2026-15410 and achieve full root compromise.

Exploitation prerequisites:

  • Internet-facing SMA 1000 appliance with vulnerable firmware.
  • No valid credentials required.

CVE-2026-15410 — Path Traversal in remove_hotfix (CVSS 7.2)

Root cause: The ctrl-service remove_hotfix workflow accepts a caller-supplied path and performs filesystem operations without normalizing the path or enforcing a chroot jail. Relative path traversal sequences allow the caller to escape the hotfix storage directory and operate on arbitrary files.

The privilege-escalation process consists of the following stages:

  1. The attacker first gains access to ctrl-service through the WebSocket tunnel established using CVE-2026-15409.
  2. A malicious remove_hotfix request is sent containing a crafted path-traversal payload such as ../../../../../tmp/1234.sh.
  3. The vulnerable service constructs a filesystem path using the attacker-controlled input.
  4. Because the path is not normalized or validated, it resolves outside the intended hotfix directory.
  5. The attacker targets a staged payload located in /tmp, causing ctrl-service to execute it with elevated privileges.
  6. The staged payload executes as root, providing complete control over the appliance.

CVE-2026-15410 attack flow

Successful exploitation allows an attacker to:

  • Escape the intended hotfix directory.
  • Access arbitrary filesystem locations.
  • Execute attacker-controlled files with root privileges.
  • Transition from a low-privileged service account to full system compromise.
  • Deploy malware, establish persistence, harvest credentials, and modify appliance configuration.

Exploitation prerequisites:

  • Reachability of ctrl-service, typically through the localhost tunnel opened by CVE-2026-15409.
  • A crafted remove_hotfix request with a malicious path.

Observed exploit artifact: /tmp/hypdate.b64 contained the encoded exploit for this flaw.

Impact Assessment

Credential Exposure

With root access, the attacker can read the appliance credential store, intercept usernames and passwords processed during authentication, and capture session tokens or MFA state. The observed use of tcpdump against unencrypted LDAP traffic demonstrates active harvesting of domain credentials traversing the appliance.

Remote Code Execution

Unauthenticated attackers can execute arbitrary operating-system commands as root. This enables deployment of cryptominers, ransomware staging tools, persistence mechanisms, and additional tooling directly on the trusted VPN gateway.

Network Traffic Interception

Root access permits packet capture on appliance interfaces. Sensitive traffic—including LDAP binds, RADIUS, authentication sessions, and internal application traffic—can be intercepted, decrypted if unencrypted, and exfiltrated.

Persistence

Setuid binaries, Python injectors, modified init scripts, and NGINX Unit configuration changes can survive reboots and may persist after a superficial firmware upgrade if not remediated. A patched appliance that still contains ROOTRUN or KNUCKLEBALL remains compromised.

Lateral Movement

The VPN appliance is positioned to route into internal networks and authenticate to directory services. Compromised credentials and proxy tunnels can be leveraged to move laterally to domain controllers, file servers, workstations, and cloud identity providers.

Business Impact

Successful exploitation can lead to unauthorized network access, data theft, service disruption, ransomware deployment, reputational damage, and regulatory exposure. Because VPN appliances are critical-path infrastructure for remote work, their compromise carries high operational-downtime risk.

Detection and Threat Hunting

Organizations should proactively hunt for signs of compromise on SMA 1000 appliances, especially those that were internet-facing and unpatched between June 22, 2026, and the patch application date. The matrix below summarizes where to look across network, host, and log data.

Network Indicators

  • Inbound HTTP requests to /wsproxy containing bmID=-3389 and User-Agent strings with SMA Connect Agent from unexpected source IPs.
  • WebSocket 101 responses in extraweb_access.log for /wsproxy with host=0.0.0.0, 127.0.0.1, ::ffff:127.0.0.1, or localhost and port=1050 or port=8188.
  • POST /__api__/login and POST /__api__/logout returning HTTP 200.
  • Requests carrying the gating user-agent: Mozilla/6.0 (Windows NT 11.0; Win64; x64) AppleWebKit/1537.136 (KHTML, like Gecko) Chrome/149.0.0.1 Safari/1537.136.
  • Outbound or internal proxying traffic patterns consistent with Suo5 tunneling.
  • Unexpected HTTPS requests to /workplace/error.jsp or /workplace/dialogs/errorDialog.jsp.

Host Indicators

  • Presence of /usr/bin/xzfind or any unexpected setuid ELF binary. Hunt with: find / -perm -4000 -type f.
  • Presence of /usr/lib/python3.11/site-packages/deploy_new.py or embedded JAR archives.
  • Unexpected files in /tmp and /var/tmp, such as /tmp/hypdate.b64, /tmp/agent_wp8.jar, /tmp/agent_wp9.jar, /tmp/1234.sh, or /var/tmp/lib.sh.
  • Modifications to /etc/init.d/workplace or /var/lib/unit/conf.json (look for routes proxying to http://127.0.0.1:8085).
  • New JSP files under /workplace/ directories.
  • Unexpected tcpdump processes or network-capture activity on TCP/389.

Log Analysis

  • Review appliance access logs for repeated /wsproxy requests from external source addresses.
  • Correlate authentication logs with unusual User-Agent strings or URI parameters.
  • Monitor ctrl-service.log for remove_hotfix entries referencing path traversal such as ../../../../../tmp/1234.sh.
  • Monitor for unexpected child processes spawned by CouchDB, ctrl-service, or NGINX Unit workers.
  • Examine tcpdump or packet-capture activity initiated by appliance service accounts.
  • Review access_servers.log for WebSocket connection messages to backend ports 1050 and 8188.

Remediation and Hardening

Organizations running affected SonicWall SMA 1000 appliances should treat this as an active, high-severity incident. Patching alone is not sufficient if the appliance was already exploited. Administrators must combine patching with compromise assessment, credential rotation, and hardening.

Immediate Response Actions

  1. Patch immediately. Upgrade SMA 1000 appliances to 12.4.3-03453 or later or 12.5.0-02835 or later through MySonicWall. Verify the installed version through the management interface or CLI.
  2. Assume compromise for internet-facing, unpatched appliances. Any appliance exposed to the internet on affected firmware before patching should be investigated using the IOCs listed above.
  3. Hunt for the IOCs. Inspect the filesystem for ROOTRUN, KNUCKLEBALL, ORANGETAIL paths, modified init scripts, and NGINX Unit configuration changes. Check for unexpected setuid binaries and tcpdump activity. Use Volexity’s published YARA signatures where available.
  4. Rebuild if compromised. If compromise is confirmed, the safest remediation is to factory-reset the appliance, reimage with patched firmware, and restore configuration from a known-good backup taken before the vulnerable firmware branches (12.4.3-03245 and 12.5.0-02283). Do not restore from backups that may include implanted persistence.
  5. Rotate credentials. Reset all credentials processed or stored by the appliance:
    1. SMA administrator passwords.
    2. Directory-service bind credentials (LDAP, RADIUS, Active Directory).
    3. User passwords for accounts that authenticated during the exposure window.
    4. Certificates and API keys configured on the appliance.
    5. TOTP/MFA tokens and seeds.
  1. Review access logs. Identify external source addresses that interacted with /wsproxy or used unusual parameters, and correlate with internal authentication and lateral-movement activity.

Hardening Measures

  • Restrict internet exposure. Place SMA appliances behind a reverse proxy, VPN, or zero-trust access gateway. Restrict inbound access to trusted source IP ranges where possible.
  • Segment appliance management. Ensure management interfaces and internal services are not reachable from untrusted networks.
  • Enable robust logging. Forward appliance logs to a SIEM with alerting on /wsproxy access, unusual User-Agent strings, and file-system integrity changes.
  • Monitor integrity. Deploy file-integrity monitoring on critical paths: /usr/bin, /usr/lib/python3.11/site-packages, /etc/init.d, /var/lib/unit, and /workplace.
  • Encrypt directory traffic. Move LDAP and RADIUS traffic to encrypted transports to reduce the value of appliance-level packet capture.
  • Update IR playbooks. Include appliance compromise scenarios, offline forensic imaging, and rapid credential-rotation workflows.

Conclusion

The July 2026 SonicWall SMA zero-day cluster is an urgent, credible, and actively exploited threat to a critical class of enterprise remote-access infrastructure. The chain demonstrates how a single pre-authentication WebSocket proxy bypass can be combined with a path-traversal privilege-escalation flaw to transform an unauthenticated internet request into full root control of a VPN appliance.

Immediate patching of SMA 1000 appliances to 12.4.3-03453+ or 12.5.0-02835+ is non-negotiable. Administrators should assume that any internet-facing, unpatched appliance running vulnerable firmware during the exposure window is either compromised or under active targeting. Patching must be paired with comprehensive threat hunting, credential rotation, integrity verification, and—if compromise is confirmed—appliance rebuild.

In the long term, organizations must re-evaluate how they expose and monitor VPN concentrators, treat edge appliances as high-value targets, and ensure that incident-response playbooks account for root-level compromise of trusted network gateways. Defense in depth—combining timely patching, strict exposure management, robust logging, encrypted directory services, and resilient recovery plans—is essential to stay ahead of actors such as UTA0533 and INC Ransomware.

As of August 1, 2026, Resecurity observes a continuous trend of ransomware groups, leveraging these vulnerabilities. We recommend that organizations establish proactive mitigation measures and ongoing cyber threat intelligence (CTI) collection to increase awareness of their latest TTPs and IOCs.

Boletín informativo

Mantente al día con las últimas noticias y desarrollos en ciberseguridad.

Al suscribirme, entiendo y acepto que mis datos personales serán recopilados y procesados de acuerdo con la Privacidad y las Política de Cookies

Arquitectura en la nube
Arquitectura en la nube
445 S. Figueroa Street
Los Angeles, CA 90071
Google Maps
Contáctenos completando el formulario
Prueba los productos de Resecurity hoy con prueba gratuita
Resecurity
Cerrar
¡Hola! Estoy aquí para responder tus preguntas y ayudarte.
Antes de empezar, ¿podrías indicarnos tu nombre y correo electrónico?