Activity timeline
UTA0533 appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 2 of 2 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
- T1078 Valid Accounts — Persistenceobserved in 2 of 2 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1090.001 Proxy: Internal Proxy — Command and Controlobserved in 2 of 2 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 2 tracked threats
- T1111 Multi-Factor Authentication Interception — Credential Accessobserved in 2 of 2 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
- T1203 Exploitation for Client Execution — Executionobserved in 2 of 2 tracked threats
- T1210 Exploitation of Remote Services — Lateral Movementobserved in 2 of 2 tracked threats
Tracked threats
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day ExploitationCRITICAL
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively ExploitedCRITICAL