SYMBOLCOMMON_NAMEaka. SYNONYMS

UTA0533  (Back to overview)


UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.


Associated Families

There are currently no families associated with this actor.


References
2026-07-17VolexitySean Koessel, Steven Adair
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
Behinder UTA0533

Credits: MISP Project