type: entity ยท created: 2026-07-20 ยท updated: 2026-07-20 ยท tags: [apt-group, threat-actor, vpn-exploitation, zero-day] ยท confidence: medium ยท affected_sectors: [technology, government, defence] ยท au_impact: true
UTA0533
UTA0533 is a previously undocumented threat actor tracked by Volexity that exploited two SonicWall SMA 1000 series VPN zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) as early as June 22, 2026.
Attribution
| Field | Detail |
|---|---|
| Tracked by | Volexity |
| Designation | UTA0533 |
| Status | Previously undocumented |
| Confidence | Medium โ single-source tracking by Volexity (Tier 2) |
Activity
- Exploited SonicWall SMA 1000 series VPN appliances
- Used a two-vulnerability chain: CVE-2026-15409 (CVSS 10.0) + CVE-2026-15410 (CVSS 7.2)
- Achieved arbitrary command execution and full device takeover
- First observed exploitation: June 22, 2026 โ before patches were available
- Patches released by SonicWall the week of July 19, 2026
TTPs
- Zero-day exploitation of edge network appliances
- Chained vulnerabilities for complete compromise
- Targeting VPN concentrators โ devices that bridge external access to internal networks
Significance
VPN appliances are frequently targeted as initial access vectors because they sit at the network perimeter and have broad network access once compromised. The CVSS 10.0 rating of CVE-2026-15409 makes this an exceptionally severe vulnerability chain.
The fact that exploitation began nearly a month before disclosure suggests either a sophisticated threat actor with zero-day research capabilities, or access to a commercial exploit broker.
Related Pages
- Sandworm โ Russian APT known for VPN appliance targeting
- Cisa Acsc Russian Network Devices โ Joint advisory on Russian targeting of network devices
- Fortibleed โ Fortinet credential exposure (related perimeter device compromise)