CARDS
CARDS
Source-specific cluster created to prevent attribution collapse. Dark Reading reports that Rapid7 associated activity with INC; Volexity reporting on UTA0533 is retained as a separate evidence line.
Decision Context
Source-specific cluster created to prevent attribution collapse. Dark Reading reports that Rapid7 associated activity with INC; Volexity reporting on UTA0533 is retained as a separate evidence line.
Actor Card Detail
Entity Type
No public RaaS identity is established for UTA0533. Do not merge this Volexity activity-cluster label with INC Ransom.
First Seen
Observed by Volexity beginning June 22, 2026
Last Seen
July 2026 public reporting
Origin
Unknown
Motivation
Unknown; observed activity supported access, credential theft, proxying, and lateral movement.
Primary Access Pattern
Internet-facing SonicWall SMA1000 secure remote-access appliances and their downstream identity/network trust.
Objective
Unknown; observed activity supported access, credential theft, proxying, and lateral movement.
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases
Source Boundary
volexity.com is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure
Target Sectors
Associated Activity
ATT&CK IDs
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| SonicWall SMA1000 Zero-Day Exploitation Campaign2,4,3,1,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 | SonicWall SMA1000 Zero-Day Exploitation Campaign is retained in the campaign database for INC Ransom. SonicWall, Rapid7, and Volexity establish a July CVE-2026-15409/CVE-2026-15410 exploitation chain that can produce root appliance compromise. Source-qualified reporting separately associates continued weaponization with INC Ransom, while Volexity tracks its observed activity as UTA0533. Hunt.io adds a separate unattributed post-disclosure CVE-2026-15409 cluster reconstructed from attacker infrastructure: 250 exploitable target identifiers, LDAP configuration recovered from 168 targets, SAM/LSA theft in at least nine Active Directory domains, and full DCSync in five. Hunt.io does not establish CVE-2026-15410 use, ransomware, INC, UTA0533, or country attribution. |
Indicators
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar | N/A | 0 | Profile retained; no SOCRadar IOC count currently stored. |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| volexity.com | UTA0533 | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | UTA0533 | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for UTA0533.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | Volexity SMA1000 zero-day analysis https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ | Campaign Analyses |
| 2 | SonicWall PSIRT SNWLID-2026-0008 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisories |
| 3 | Rapid7 SMA1000 zero-day analysis https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/ | Campaign Analyses |
| 4 | Known Exploited Vulnerabilities Catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 5 | INC ransomware exploits SonicWall SMA zero-days https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days | Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 6 | SonicWall warns of exploited SMA1000 zero-days https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/ | BleepingComputer campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 7 | SMA1000 zero-days used to deploy custom malware https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/ | BleepingComputer campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 8 | SMA appliances targeted in zero-day attacks https://www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410/ | Help Net Security campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 9 | Urgent SMA patch warning for two zero-days https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/ | SecurityWeek campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 10 | Two SonicWall SMA 1000 zero-days exploited https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.html | The Hacker News campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 11 | SMA1000 product notice and recovery guidance https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ | SonicWall campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 12 | From WSProxy to Root: INC ransomware and SonicWall SMA exploit chain https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain | Resecurity campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 13 | INC ransomware emerges as dominant actor exploiting SMA1000 flaws https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html | The Hacker News campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 14 | SonicWall PSIRT SNWLID-2026-0016 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 | SonicWall PSIRT campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 15 | NVD CVE-2026-83548 https://nvd.nist.gov/vuln/detail/CVE-2026-83548 | NIST NVD campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 16 | NVD CVE-2026-83549 https://nvd.nist.gov/vuln/detail/CVE-2026-83549 | NIST NVD campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 17 | Canadian Centre for Cyber Security AV26-872 Update 1 https://www.cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-872 | Canadian Centre for Cyber Security campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 18 | Rapid7 September SMA1000 vulnerability analysis https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/ | Rapid7 campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 19 | runZero Rapid Response: SMA1000 September vulnerabilities https://help.runzero.com/docs/em-rapid-response/ | runZero campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 20 | Hunt.io UK Council Attack Linked to SonicWall SMA 1000 Campaign https://hunt.io/blog/sonicwall-sma1000-uk-council-attack | Hunt.io campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 21 | BBC News council cyberattack disclosure https://www.bbc.co.uk/news/articles/c4gk85ey55yo | BBC News campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |