Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-20 ยท updated: 2026-07-20 ยท tags: [apt-group, threat-actor, vpn-exploitation, zero-day] ยท confidence: medium ยท affected_sectors: [technology, government, defence] ยท au_impact: true

UTA0533

UTA0533 is a previously undocumented threat actor tracked by Volexity that exploited two SonicWall SMA 1000 series VPN zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) as early as June 22, 2026.

Attribution

Field Detail
Tracked by Volexity
Designation UTA0533
Status Previously undocumented
Confidence Medium โ€” single-source tracking by Volexity (Tier 2)

Activity

  • Exploited SonicWall SMA 1000 series VPN appliances
  • Used a two-vulnerability chain: CVE-2026-15409 (CVSS 10.0) + CVE-2026-15410 (CVSS 7.2)
  • Achieved arbitrary command execution and full device takeover
  • First observed exploitation: June 22, 2026 โ€” before patches were available
  • Patches released by SonicWall the week of July 19, 2026

TTPs

  • Zero-day exploitation of edge network appliances
  • Chained vulnerabilities for complete compromise
  • Targeting VPN concentrators โ€” devices that bridge external access to internal networks

Significance

VPN appliances are frequently targeted as initial access vectors because they sit at the network perimeter and have broad network access once compromised. The CVSS 10.0 rating of CVE-2026-15409 makes this an exceptionally severe vulnerability chain.

The fact that exploitation began nearly a month before disclosure suggests either a sophisticated threat actor with zero-day research capabilities, or access to a commercial exploit broker.

Related Pages