CARDS
CARDS
Source-specific cluster created to prevent attribution collapse. Dark Reading reports that Rapid7 associated activity with INC; Volexity reporting on UTA0533 is retained as a separate evidence line.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Entity Type
No public RaaS identity is established for UTA0533. Do not merge this Volexity activity-cluster label with INC Ransom.
First Seen
Observed by Volexity beginning June 22, 2026
Last Seen
July 2026 public reporting
Profile Updated
Jul 23, 2026, 2:30 PM EDT
Victim Count
Not available
Origin
Unknown
Motivation
Unknown; observed activity supported access, credential theft, proxying, and lateral movement.
Primary Access Pattern
Internet-facing SonicWall SMA1000 secure remote-access appliances and their downstream identity/network trust.
Objective
Unknown; observed activity supported access, credential theft, proxying, and lateral movement.
Identity
Aliases
Source Boundary
volexity.com is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure
Target Sectors
Associated Activity
ATT&CK IDs
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| SonicWall SMA1000 Zero-Day Exploitation Campaign2,4,3,1,5 | SonicWall SMA1000 Zero-Day Exploitation Campaign is retained in the campaign database for INC Ransom. Attackers chained unauthenticated CVE-2026-15409 with CVE-2026-15410 to move from WebSocket proxy access to root-level execution on SonicWall SMA1000 appliances. Rapid7's public technical post confirms active exploitation, credential/session/TOTP theft, and lateral movement. Dark Reading reports that Rapid7 tied the activity to INC Ransom and that one case progressed to ransomware. Volexity independently tracks observed activity as UTA0533. |
Indicators
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar | N/A | 0 | Profile retained; no SOCRadar IOC count currently stored. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| volexity.com | UTA0533 | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | UTA0533 | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | Volexity SMA1000 zero-day analysis https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ | Campaign Analyses |
| 2 | SonicWall PSIRT SNWLID-2026-0008 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | Vendor Advisories |
| 3 | Rapid7 SMA1000 zero-day analysis https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/ | Campaign Analyses |
| 4 | CISA KEV Catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 5 | Dark Reading INC reporting https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for UTA0533.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |